Vulnerabilities > Metabase > Metabase > 0.13.3

DATE CVE VULNERABILITY TITLE RISK
2023-08-04 CVE-2023-37470 Code Injection vulnerability in Metabase
Metabase is an open-source business intelligence and analytics platform.
network
low complexity
metabase CWE-94
critical
9.8
2023-07-21 CVE-2023-38646 Unspecified vulnerability in Metabase
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level.
network
low complexity
metabase
critical
9.8
2023-05-18 CVE-2023-32680 Missing Authentication for Critical Function vulnerability in Metabase
Metabase is an open source business analytics engine.
network
low complexity
metabase CWE-306
critical
9.6
2023-01-28 CVE-2023-23628 Information Exposure vulnerability in Metabase
Metabase is an open source data analytics platform.
network
low complexity
metabase CWE-200
4.1
2023-01-28 CVE-2023-23629 Improper Privilege Management vulnerability in Metabase
Metabase is an open source data analytics platform.
network
low complexity
metabase CWE-269
6.3
2022-10-26 CVE-2022-43776 Server-Side Request Forgery (SSRF) vulnerability in Metabase
The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks.
network
low complexity
metabase CWE-918
6.5
2018-11-15 CVE-2018-0697 Cross-site Scripting vulnerability in Metabase
Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
metabase CWE-79
4.3