Apache Superset allows privileged users to conduct error-based SQL Injection
Modified: 7/13/2026
package
pkg:pypi/apache-superset
Apache Superset allows privileged users to conduct error-based SQL Injection
Modified: 7/13/2026
Apache Superset allows authenticated users to view sensitive data without explicit permissions
Modified: 7/13/2026
Apache Superset: Improper error handling on alerts
Modified: 7/7/2026
Apache Superset Open Redirect vulnerability
Modified: 7/7/2026
Apache Superset server arbitrary file read
Modified: 7/7/2026
Insufficiently Protected Credentials in Apache Superset
Modified: 2/5/2025
Apache Superset Incorrect Authorization vulnerability
Modified: 7/7/2026
Apache Superset: Error verbosity exposes metadata in analytics databases
Modified: 7/7/2026
Apache Superset vulnerable to improper SQL authorization
Modified: 7/7/2026
Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
Modified: 7/7/2026
Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
Modified: 7/7/2026
Apache Superset Improper Authorization allows low-privileged users to bypass access controls
Modified: 7/13/2026
Apache Superset: Improper authorization validation on dashboards and charts import
Modified: 7/7/2026
Apache Superset allowed for database connections password leak for authenticated users
Modified: 2/5/2025
Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
Modified: 7/13/2026
Apache Superset Server Side Request Forgery vulnerability
Modified: 7/7/2026
Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
Modified: 7/7/2026
Apache superset missing check for default SECRET_KEY
Modified: 7/7/2026
Improper Encoding or Escaping of Output in Apache Superset
Modified: 2/5/2025
Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints
Modified: 7/7/2026
Apache Superset allows authenticated users to access metadata they have no permission to
Modified: 7/7/2026
Plaintext password leak in Apache Superset
Modified: 2/5/2025
Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
Modified: 7/7/2026
Apache Superset is vulnerable to Cross-Site Scripting (XSS)
Modified: 7/7/2026
Apache Superset vulnerable to Improper Authorization
Modified: 7/7/2026
Apache Superset has Improper Access Control
Modified: 7/7/2026
Apache Superset: Improper authorization bypass on row level security via SQL Injection
Modified: 7/7/2026
Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
Modified: 7/7/2026
Apache Superset has incorrect authorization check
Modified: 7/7/2026
Apache Superset uncontrolled resource consumption
Modified: 7/7/2026
Apache Superset has improper default REST API permission for Gamma users
Modified: 7/7/2026
Users can view database names in Apache Superset
Modified: 9/5/2024
Apache Superset vulnerable to Cross-site Scripting
Modified: 7/7/2026
Apache Superset data query improperly discloses database schema information to low-privileged guest user
Modified: 8/13/2026
Apache Superset users may incorrectly create resources using the import charts feature
Modified: 7/7/2026
Apache Superset OS Command Injection
Modified: 2/5/2025
Apache Superset vulnerable to Exposure of Sensitive Information
Modified: 7/7/2026
Apache Superset may expose internal traces on REST API endpoints
Modified: 7/7/2026
Apache Superset's SQL Alchemy connector vulnerable to SQL Injection
Modified: 7/7/2026
Apache Superset - Elevation of Privilege
Modified: 7/8/2026
Apache Superset Cross-site Scripting (XSS) vulnerability on the Explore page
Modified: 2/5/2025
Apache Superset Open Redirect vulnerability
Modified: 7/7/2026
Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Modified: 7/7/2026
Apache Superset Deserialization of Untrusted Data vulnerability
Modified: 7/7/2026
Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
Modified: 7/7/2026
Apache Superset Improper Input Validation vulnerability
Modified: 7/7/2026
Apache Superset vulnerable to Injection
Modified: 7/7/2026
Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
Modified: 7/7/2026
Apache Superset Server-Side Request Forgery vulnerability
Modified: 7/7/2026
Information disclosure in Apache Superset
Modified: 2/5/2025
Apache Superset incorrect write permissions vulnerability
Modified: 7/7/2026
Apache Superset SQL injection vulnerability
Modified: 7/7/2026
Apache Superset: Improper Neutralization of custom SQL on embedded context
Modified: 7/7/2026
Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
Modified: 9/10/2026
Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
Modified: 7/13/2026
Users able to query database metadata in Apache Superset
Modified: 9/5/2024
Open Redirect in Apache Superset
Modified: 7/13/2026
Apache Superset SQL Injection when template processing is enabled
Modified: 2/5/2025
Cross-site Scripting in Apache superset
Modified: 6/29/2026
Apache Superset vulnerable to improper data authorization
Modified: 7/7/2026
Apache Superset has Incorrect Default Permissions
Modified: 7/7/2026
Apache Superset Stored XSS on Dashboard markdown
Modified: 2/5/2025
Apache Superset Allows Ownership Takeover
Modified: 7/7/2026
SQL injection in apache-superset
Modified: 2/5/2025
Apache Superset Cross-site Scripting vulnerability
Modified: 7/7/2026
Apache Superset: Improper data authorization when creating a new dataset
Modified: 7/7/2026
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 6/10/2026
Modified: 2/5/2025
Modified: 2/5/2025
Modified: 2/5/2025
Modified: 7/13/2026
Modified: 2/5/2025
Modified: 2/5/2025
Modified: 2/5/2025
Modified: 2/5/2025
Apache Superset Improper Authorization allows low-privileged users to bypass access controls
Modified: 7/13/2026
Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
Modified: 7/13/2026
Apache Superset allows privileged users to conduct error-based SQL Injection
Modified: 7/13/2026
Apache Superset allows authenticated users to view sensitive data without explicit permissions
Modified: 7/13/2026
Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
Modified: 7/13/2026
Modified: 2/5/2025
Modified: 2/5/2025
Apache Superset Incorrect Authorization vulnerability
Modified: 7/7/2026
Apache Superset: Error verbosity exposes metadata in analytics databases
Modified: 7/7/2026
Apache Superset vulnerable to improper SQL authorization
Modified: 7/7/2026
Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
Modified: 7/7/2026
Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
Modified: 7/7/2026
Apache Superset: Improper authorization validation on dashboards and charts import
Modified: 7/7/2026
Apache Superset Server Side Request Forgery vulnerability
Modified: 7/7/2026
Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
Modified: 7/7/2026
Apache superset missing check for default SECRET_KEY
Modified: 7/7/2026
Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
Modified: 7/7/2026
Apache Superset vulnerable to Improper Authorization
Modified: 7/7/2026
Apache Superset: Improper authorization bypass on row level security via SQL Injection
Modified: 7/7/2026
Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
Modified: 7/7/2026
Apache Superset has incorrect authorization check
Modified: 7/7/2026
Apache Superset uncontrolled resource consumption
Modified: 7/7/2026
Apache Superset has improper default REST API permission for Gamma users
Modified: 7/7/2026