Metabase
9 CVEs tracked since 2022. Since Apr 2022, none of them reached CISA KEV.
Metabase CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-04 | 3 | 0 |
| 2022-05 | null or fewer | |
| 2022-06 | null or fewer | |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | 6 | 0 |
Products
The products that kept showing up in Metabase's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Metabase.
- CVE-2026-92813Metabase through 0.63.18 SSRF via GeoJSON URL validation bypass4.9
- CVE-2026-86116Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary Management API6.5
- CVE-2026-72900Metabase information exposure6.5
- CVE-2026-72899Metabase SQL injection via public card or dashboard10.0
- CVE-2026-72898Metabase SQL injection via password reset endpoint10.0
- CVE-2026-50147Metabase: Arbitrary File Read via MySQL Connection Property Injection7.6
- CVE-2026-50148Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write10.0
- CVE-2026-59826Metabase: Arbitrary Code Execution via Database Connection Detail Bypass9.1
- CVE-2026-59827Metabase: Unsafe Deserialization of H2 Query Results9.9
- CVE-2026-33725Metabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Import7.2
- CVE-2026-27464Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCE7.7
- CVE-2026-22805Metabase channel test endpoint can reach internal local addresses—
- CVE-2025-5895Metabase dom.js parseDataUri redos4.3
- CVE-2025-32382Snowflake credentials logged by the Metabase backend—
- CVE-2025-30371Metabase vulnerable to circumvention of local link access protection in GeoJson endpoint—
The record
- Peak rank
- #106 in Oct 2022
- Busiest month shown
- Oct 2022, 6 CVEs
- Months with a KEV entry
- 0 since Apr 2022
- Monthly snapshots
- 2 since 2022