CVE-2026-32252
- EPSS 0.02%
- Veröffentlicht 10.04.2026 19:17:53
- Zuletzt bearbeitet 14.04.2026 17:25:25
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.9.0, a cross-tenant authorization bypass exists in Chartbrew in GET /team/:team_id/template/generate/:project_id...
CVE-2026-30232
- EPSS 0.04%
- Veröffentlicht 10.04.2026 19:15:11
- Zuletzt bearbeitet 14.04.2026 17:26:55
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartbrew allows authenticated users to create API data connections with arbitrary URLs. The server fetches...
CVE-2026-27605
- EPSS 0.08%
- Veröffentlicht 06.03.2026 04:08:01
- Zuletzt bearbeitet 10.03.2026 14:01:09
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the application allows uploading files (project logos) without validating the file type or content....
CVE-2026-27603
- EPSS 0.07%
- Veröffentlicht 06.03.2026 04:07:49
- Zuletzt bearbeitet 10.03.2026 14:02:36
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the chart filter endpoint POST /project/:project_id/chart/:chart_id/filter is missing both verifyTo...
CVE-2026-27005
- EPSS 0.17%
- Veröffentlicht 06.03.2026 04:07:36
- Zuletzt bearbeitet 10.03.2026 14:04:01
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3, an unauthenticated attacker can inject arbitrary SQL into queries executed against databases connec...
CVE-2026-25888
- EPSS 0.37%
- Veröffentlicht 06.03.2026 04:07:26
- Zuletzt bearbeitet 10.03.2026 14:05:56
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via a vulnerable API. This issue has been patched in...
CVE-2026-25887
- EPSS 0.14%
- Veröffentlicht 06.03.2026 04:07:12
- Zuletzt bearbeitet 10.03.2026 14:07:21
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via the MongoDB dataset Query. This issue has been p...
CVE-2026-25877
- EPSS 0.04%
- Veröffentlicht 06.03.2026 04:07:01
- Zuletzt bearbeitet 10.03.2026 14:09:25
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, the application performs authorization checks based solely on the project_id parameter when handlin...