Sqlbot
15 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Sqlbot, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Sqlbot CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 5 |
| 2026-04 | 1 |
| 2026-05 | 2 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 1 |
| 2026-09 | 5 |
Severity
How the 15 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High5
- Medium5
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Sqlbot.
- CVE-2026-93660SQLBot through 1.10.1 Improper Access Control via Dashboard Update6.5
- CVE-2026-53557SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Command Execution—
- CVE-2026-53555Stored XSS via SVG Upload—
- CVE-2026-53556SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary File Read—
- CVE-2026-53554SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import Processing—
- CVE-2026-72743SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html5.4
- CVE-2026-42463SQLBot: Unauthorized Access Vulnerability8.1
- CVE-2026-33324SQLBot prompt injection allows arbitrary SQL execution and remote code execution8.8
- CVE-2026-5417Dataease SQLbot Elasticsearch es_engine.py get_es_data_by_http server-side request forgery4.7
- CVE-2026-32950SQLBot: RCE via SQL Injection in Excel Upload Endpoint8.8
- CVE-2026-32949SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL7.5
- CVE-2026-32622SQLBot: Remote Code Execution via Terminology Poisoning8.8
- CVE-2025-15598Dataease SQLBot JWT Token auth.py validateEmbedded signature verification3.7
- CVE-2025-15597Dataease SQLBot API Endpoint assistant.py access control6.3
- CVE-2025-69285SQLBot uploadExcel Endpoint has Unauthenticated Arbitrary File Upload vulnerability6.1
Product grouping is registry-driven, with AI assist and human review. How it works