datagear vulnerabilities
CVEs whose affected-version data names the datagear package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-92566High· 8.2PoCDataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI
DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers ca…
▾ Midnightdatageartech · datagearEPSS 0.49%via NVD
CVE-2023-7299Medium· 6.3A vulnerability was found in DataGear up to 4.60
A vulnerability was found in DataGear up to 4.60. It has been declared as critical. This vulnerability affects unknown code of the file /dataSet/resolveSql. The manipulation of the argument sql leads to sql injection. The attack can be i…
▾ Sunlitdatagear · datagearEPSS 0.64%via NVD