CVE-2025-58065
- EPSS 0.07%
- Published 11.09.2025 17:55:48
- Last modified 24.09.2025 13:41:42
Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to use OAuth, LDAP, or other non-database authentication methods, the password reset endpoint remains registered and accessible, des...
CVE-2025-32962
- EPSS 0.05%
- Published 16.05.2025 13:51:55
- Last modified 19.09.2025 18:04:24
Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated actor to perform an open redirect by manipulating the Host header in HTTP requests. Flask-AppBuilder 4...
CVE-2025-24023
- EPSS 0.06%
- Published 03.03.2025 16:15:41
- Last modified 07.03.2025 19:37:57
Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerabili...
CVE-2024-27083
- EPSS 0.63%
- Published 29.02.2024 01:44:19
- Last modified 01.04.2025 15:22:28
Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth log...
CVE-2024-25128
- EPSS 0.4%
- Published 29.02.2024 01:44:14
- Last modified 21.11.2024 09:00:18
Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID servic...
CVE-2023-29005
- EPSS 0.25%
- Published 10.04.2023 21:15:07
- Last modified 07.03.2025 14:37:51
Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED = True`, and settin...
CVE-2022-31177
- EPSS 0.36%
- Published 01.08.2022 19:15:08
- Last modified 07.03.2025 14:37:51
Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by their salted and hashed passwords strings. These filters could be made ...
CVE-2022-24776
- EPSS 0.35%
- Published 24.03.2022 20:15:09
- Last modified 07.03.2025 14:37:51
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue is fixed in ...
CVE-2022-21659
- EPSS 0.26%
- Published 31.01.2022 21:15:09
- Last modified 05.05.2025 17:17:47
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate existing accoun...
CVE-2021-41265
- EPSS 0.33%
- Published 09.12.2021 17:15:07
- Last modified 07.03.2025 14:37:51
Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authen...