vciy

CVEs we hold for Metabase

Records whose assigning authority named Metabase as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-92813Metabase through 0.63.18 SSRF via GeoJSON URL validation bypassMetabase
CVE-2026-86116Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary Management APImetabase
CVE-2026-72900Metabase information exposureMetabase
CVE-2026-72899Metabase SQL injection via public card or dashboardMetabase
CVE-2026-72898Metabase SQL injection via password reset endpointMetabase
CVE-2026-59827Metabase: Unsafe Deserialization of H2 Query Resultsmetabase
CVE-2026-59826Metabase: Arbitrary Code Execution via Database Connection Detail Bypassmetabase
CVE-2026-50148Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Writemetabase
CVE-2026-50147Metabase: Arbitrary File Read via MySQL Connection Property Injectionmetabase
CVE-2026-33725Metabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Importmetabase
CVE-2026-27464Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCEmetabase
CVE-2026-22805Metabase channel test endpoint can reach internal local addressesmetabase
CVE-2025-5895Metabase dom.js parseDataUri redosn/a Metabase
CVE-2025-32382Snowflake credentials logged by the Metabase backendmetabase
CVE-2025-30371Metabase vulnerable to circumvention of local link access protection in GeoJson endpointmetabase
CVE-2025-27141Metabase Enterprise Edition allows cached questions to leak data to impersonated usersmetabase
CVE-2024-55951Metabase sandboxed users could see filter values from other sandboxed usersmetabase
CVE-2023-37470Metabase vulnerable to remote code execution via POST /api/setup/validate API endpointmetabase
CVE-2023-32680Missing SQL permissions check in metabasemetabase
CVE-2023-23629Metabase subject to Improper Privilege Managementmetabase
CVE-2023-23628Metabase subject to Exposure of Sensitive Information to an Unauthorized Actormetabase
CVE-2022-43776no title heldn/a Metabase
CVE-2022-39362Metabase vulnerable to arbitrary SQL execution from queryhashmetabase
CVE-2022-39361Metabase vulnerable to Remote Code Execution via H2metabase
CVE-2022-39360Metabase SSO users able to circumvent IdP login by doing password resetmetabase
CVE-2022-39359Metabase's GeoJSON validation doesn't prevent redirects to blocked URLsmetabase
CVE-2022-39358Metabase vulnerable to circumvention of Locked parameter in Signed Embeddingmetabase
CVE-2022-24855XSS vulnerability in Metabasemetabase
CVE-2022-24854Database bypassing any permissions in Metabase via SQlite attachmetabase
CVE-2022-24853File system exposure in Metabasemetabase
CVE-2021-41277GeoJSON URL validation can expose server files and environment variables to unauthorized usersmetabase
CVE-2018-0697no title heldMetabase, Inc. Metabase

32 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.