apache-superset has 52 CVEs on record between 2022 and 2026. The busiest recent month was February 2026 with 5. The median CVSS is 5.4 (medium), with 1 rated critical. 2% have been exploited in the wild, in line with the corpus average.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 2% vs 1% corpus
- Median CVSS
- 5.4
- Publish → KEV
- —(1)
- Last 90 days
- 0 prev 0
Products
- apache-superset 52
Worst active — by depth score
CVE-2023-27524High· 8.9Apache superset missing check for default SECRET_KEY93CVE-2023-39265Medium· 6.5Apache Superset Improper Input Validation vulnerability65CVE-2023-37941Medium· 6.6Apache Superset Deserialization of Untrusted Data vulnerability55CVE-2024-53947Critical· 9.8Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions54CVE-2024-34693Medium· 6.8Apache Superset server arbitrary file read 50
apache-superset vulnerabilities
CVEs affecting apache-superset, newest first. Open any entry for full detail, references, and exploit status.
52 CVEsRSS
CVE-2026-23984HighApache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
CVE-2026-23983LowApache Superset allows authenticated users to view sensitive data without explicit permissions
Apache Superset allows authenticated users to view sensitive data without explicit permissions
CVE-2026-23980MediumPoCApache Superset allows privileged users to conduct error-based SQL Injection
Apache Superset allows privileged users to conduct error-based SQL Injection
CVE-2026-23969MediumApache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
CVE-2026-23982HighApache Superset Improper Authorization allows low-privileged users to bypass access controls
Apache Superset Improper Authorization allows low-privileged users to bypass access controls
CVE-2025-55675MediumApache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
CVE-2025-55674MediumApache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
CVE-2025-55672MediumApache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
CVE-2025-55673MediumApache Superset data query improperly discloses database schema information to low-privileged guest user
Apache Superset data query improperly discloses database schema information to low-privileged guest user
CVE-2025-48912HighApache Superset: Improper authorization bypass on row level security via SQL Injection
Apache Superset: Improper authorization bypass on row level security via SQL Injection
CVE-2025-27696High· 8.8Apache Superset Allows Ownership Takeover
Apache Superset Allows Ownership Takeover
CVE-2024-55633Medium· 6.5Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
CVE-2024-53947Critical· 9.8Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
CVE-2024-53949Medium· 6.5Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
CVE-2024-53948Medium· 5.3Apache Superset: Error verbosity exposes metadata in analytics databases
Apache Superset: Error verbosity exposes metadata in analytics databases
CVE-2024-39887Medium· 4.3PoCApache Superset vulnerable to improper SQL authorization
Apache Superset vulnerable to improper SQL authorization
CVE-2024-34693Medium· 6.8PoCApache Superset server arbitrary file read
Apache Superset server arbitrary file read
CVE-2024-28148Medium· 4.3Apache Superset Incorrect Authorization vulnerability
Apache Superset Incorrect Authorization vulnerability
CVE-2024-24779Medium· 5.0Apache Superset: Improper data authorization when creating a new dataset
Apache Superset: Improper data authorization when creating a new dataset
CVE-2024-24772Medium· 4.3Apache Superset: Improper Neutralization of custom SQL on embedded context
Apache Superset: Improper Neutralization of custom SQL on embedded context
CVE-2024-27315Medium· 4.3Apache Superset: Improper error handling on alerts
Apache Superset: Improper error handling on alerts
CVE-2024-24773Medium· 4.9Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
CVE-2024-26016Medium· 4.3Apache Superset: Improper authorization validation on dashboards and charts import
Apache Superset: Improper authorization validation on dashboards and charts import
CVE-2023-49736Medium· 6.5Apache Superset SQL injection vulnerability
Apache Superset SQL injection vulnerability
CVE-2023-49734High· 7.7Apache Superset incorrect write permissions vulnerability
Apache Superset incorrect write permissions vulnerability
CVE-2023-46104Medium· 6.5Apache Superset uncontrolled resource consumption
Apache Superset uncontrolled resource consumption
CVE-2023-42502Medium· 5.4Apache Superset Open Redirect vulnerability
Apache Superset Open Redirect vulnerability
CVE-2023-42505Medium· 4.3Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-40610High· 7.3Apache Superset - Elevation of Privilege
Apache Superset - Elevation of Privilege
CVE-2023-42504Medium· 6.5Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
Apache Superset Allocation of Resources Without Limits or Throttling vulnerability