CVE Tools

Mindsdb

12 CVEs tracked since 2024. Since Sep 2024, none of them reached CISA KEV.

Mindsdb CVEs per month

Sep 2024 to Sep 2024. Point at a month, or focus the strip and use the arrow keys.
Mindsdb CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-09120

Products

The products that kept showing up in Mindsdb's monthly top three, with their CVEs summed over those months.

  1. Mindsdb121 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Mindsdb.

  1. CVE-2026-86173MindsDB through 26.1.0 Unauthenticated SSRF via Web Crawler7.5
  2. CVE-2026-73678MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()10.0
  3. CVE-2026-27483MindsDB has Path Traversal in /api/files Leading to Remote Code Execution8.8
  4. CVE-2026-2531MindsDB File Upload security.py clear_filename server-side request forgery6.3
  5. CVE-2025-68472MindsDB has improper sanitation of filepath that leads to information disclosure and DOS8.1
  6. CVE-2024-45854MindsDB Deserialization of Untrusted Data vulnerability7.1
  7. CVE-2024-45847MindsDB Eval Injection vulnerability8.8
  8. CVE-2024-45856A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project,...9.0
  9. CVE-2024-45855Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when usi...7.1
  10. CVE-2024-45853Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when use...7.1
  11. CVE-2024-45852Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.8.8
  12. CVE-2024-45851An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases cr...8.8
  13. CVE-2024-45850An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases cr...8.8
  14. CVE-2024-45849An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases cr...8.8
  15. CVE-2024-45848An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. If a specially crafted ‘IN...8.8

The record

Peak rank
#58 in Sep 2024
Busiest month shown
Sep 2024, 12 CVEs
Months with a KEV entry
0 since Sep 2024
Monthly snapshots
1 since 2024
Mindsdb's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store