CVE-2026-33122
- EPSS 0.41%
- Veröffentlicht 16.04.2026 19:24:03
- Zuletzt bearbeitet 20.04.2026 16:40:39
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource update process. When a new table definition is added during a datasource update via /de2api/d...
CVE-2026-33121
- EPSS 0.33%
- Veröffentlicht 16.04.2026 18:16:02
- Zuletzt bearbeitet 20.04.2026 16:37:02
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource saving process. The deTableName field from the Base64-encoded datasource configuration is use...
CVE-2026-33084
- EPSS 0.33%
- Veröffentlicht 16.04.2026 18:14:07
- Zuletzt bearbeitet 20.04.2026 16:36:16
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj endpoint. The DatasetDataManage service layer directl...
CVE-2026-33083
- EPSS 0.33%
- Veröffentlicht 16.04.2026 17:52:37
- Zuletzt bearbeitet 20.04.2026 16:35:50
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related endpoints including /de2api/datasetData/enumValueDs and /de...
CVE-2026-33082
- EPSS 0.33%
- Veröffentlicht 16.04.2026 17:39:37
- Zuletzt bearbeitet 20.04.2026 16:34:56
DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export functionality. The expressionTree parameter in POST /de2api/datasetTree/exportDataset is deserialized ...
CVE-2026-32939
- EPSS 0.45%
- Veröffentlicht 20.03.2026 03:27:46
- Zuletzt bearbeitet 23.03.2026 19:25:44
DataEase is an open source data visualization analysis tool. Versions 2.10.19 and below have inconsistent Locale handling between the JDBC URL validation logic and the H2 JDBC engine's internal parsing. DataEase uses String.toUpperCase() without spec...
CVE-2026-32140
- EPSS 0.69%
- Veröffentlicht 12.03.2026 18:16:25
- Zuletzt bearbeitet 13.03.2026 19:54:40
Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject dangerous...
CVE-2026-32139
- EPSS 0.2%
- Veröffentlicht 12.03.2026 18:16:25
- Zuletzt bearbeitet 13.03.2026 16:02:45
Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload interface allows SVG uploads. However, backend validation only checks whether the XML is parseable and whether the root node is s...
CVE-2026-32137
- EPSS 0.42%
- Veröffentlicht 12.03.2026 17:53:00
- Zuletzt bearbeitet 13.03.2026 16:03:02
Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated into the SQL statement without any filtering or parameterization. Since tableName is a user...
CVE-2026-23958
- EPSS 0.48%
- Veröffentlicht 22.01.2026 01:42:11
- Zuletzt bearbeitet 17.02.2026 16:28:47
Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT signing secret. This deterministic secret derivation allows an attacker to brute-force the admin’s pas...