DataEase has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 6.3 (medium). None have a confirmed exploitation report. Most affected products: SQLBot (5), DataEase (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Worst active — by depth score
CVE-2026-53554High· 7.3SQLBot is an intelligent Text-to-SQL system based on large language models and RAG52CVE-2026-53556Medium· 6.0SQLBot is an intelligent Text-to-SQL system based on large language models and RAG45CVE-2026-53557High· 7.7SQLBot is an intelligent Text-to-SQL system based on large language models and RAG42CVE-2026-53555Medium· 5.1SQLBot is an intelligent Text-to-SQL system based on large language models and RAG40CVE-2026-93660Medium· 6.5SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards36
DataEase vulnerabilities
CVEs affecting DataEase, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-93660Medium· 6.5SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards
SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to…
CVE-2026-53557High· 7.7SQLBot is an intelligent Text-to-SQL system based on large language models and RAG
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/…
CVE-2026-53556Medium· 6.0PoCSQLBot is an intelligent Text-to-SQL system based on large language models and RAG
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_n…
CVE-2026-53555Medium· 5.1PoCSQLBot is an intelligent Text-to-SQL system based on large language models and RAG
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through PATCH /api/v1/system/assistant/ui, and SQLBot stores the …
CVE-2026-53554High· 7.3PoCSQLBot is an intelligent Text-to-SQL system based on large language models and RAG
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename …
CVE-2023-40772Medium· 4.3PoCA directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.
A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.