CVEs we hold for Metabase
Records whose assigning authority named Metabase as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-92813Metabase through 0.63.18 SSRF via GeoJSON URL validation bypassMetabase CVE-2026-86116Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary Management APImetabase CVE-2026-72899Metabase SQL injection via public card or dashboardMetabase CVE-2026-72898Metabase SQL injection via password reset endpointMetabase CVE-2026-59827Metabase: Unsafe Deserialization of H2 Query Resultsmetabase CVE-2026-59826Metabase: Arbitrary Code Execution via Database Connection Detail Bypassmetabase CVE-2026-50148Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Writemetabase CVE-2026-50147Metabase: Arbitrary File Read via MySQL Connection Property Injectionmetabase CVE-2026-33725Metabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Importmetabase CVE-2026-27464Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCEmetabase CVE-2026-22805Metabase channel test endpoint can reach internal local addressesmetabase CVE-2025-32382Snowflake credentials logged by the Metabase backendmetabase CVE-2025-30371Metabase vulnerable to circumvention of local link access protection in GeoJson endpointmetabase CVE-2025-27141Metabase Enterprise Edition allows cached questions to leak data to impersonated usersmetabase CVE-2024-55951Metabase sandboxed users could see filter values from other sandboxed usersmetabase CVE-2023-37470Metabase vulnerable to remote code execution via POST /api/setup/validate API endpointmetabase CVE-2023-23629Metabase subject to Improper Privilege Managementmetabase CVE-2023-23628Metabase subject to Exposure of Sensitive Information to an Unauthorized Actormetabase CVE-2022-39362Metabase vulnerable to arbitrary SQL execution from queryhashmetabase CVE-2022-39361Metabase vulnerable to Remote Code Execution via H2metabase CVE-2022-39360Metabase SSO users able to circumvent IdP login by doing password resetmetabase CVE-2022-39359Metabase's GeoJSON validation doesn't prevent redirects to blocked URLsmetabase CVE-2022-39358Metabase vulnerable to circumvention of Locked parameter in Signed Embeddingmetabase CVE-2022-24854Database bypassing any permissions in Metabase via SQlite attachmetabase CVE-2021-41277GeoJSON URL validation can expose server files and environment variables to unauthorized usersmetabase 32 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.