VulnSea

apache-superset has 52 CVEs on record between 2022 and 2026. The busiest recent month was February 2026 with 5. The median CVSS is 5.4 (medium), with 1 rated critical. 2% have been exploited in the wild, in line with the corpus average.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
5.4
Publish → KEV
(1)
Last 90 days
0 prev 0

Products

  • apache-superset 52
52
Total CVEs
1
Critical
1
CISA KEV
1
Exploited

apache-superset vulnerabilities

CVEs affecting apache-superset, newest first. Open any entry for full detail, references, and exploit status.

52 CVEsRSS

CVE-2026-23984High
7mo ago

Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections

Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections

Twilightapache-superset · apache-supersetEPSS 0.35%via OSV
CVE-2026-23983Low
7mo ago

Apache Superset allows authenticated users to view sensitive data without explicit permissions

Apache Superset allows authenticated users to view sensitive data without explicit permissions

Sunlitapache-superset · apache-supersetEPSS 0.40%via OSV
CVE-2026-23980MediumPoC
7mo ago

Apache Superset allows privileged users to conduct error-based SQL Injection

Apache Superset allows privileged users to conduct error-based SQL Injection

Twilightapache-superset · apache-supersetEPSS 0.61%via OSV
CVE-2026-23969Medium
7mo ago

Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine

Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine

Sunlitapache-superset · apache-supersetEPSS 0.61%via OSV
CVE-2026-23982High
7mo ago

Apache Superset Improper Authorization allows low-privileged users to bypass access controls

Apache Superset Improper Authorization allows low-privileged users to bypass access controls

Twilightapache-superset · apache-supersetEPSS 0.44%via OSV
CVE-2025-55675Medium
1y ago

Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access

Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access

Sunlitapache-superset · apache-supersetEPSS 0.53%via OSV
CVE-2025-55674Medium
1y ago

Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions

Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions

Sunlitapache-superset · apache-supersetEPSS 0.69%via OSV
CVE-2025-55672Medium
1y ago

Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability

Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability

Sunlitapache-superset · apache-supersetEPSS 0.68%via OSV
CVE-2025-55673Medium
1y ago

Apache Superset data query improperly discloses database schema information to low-privileged guest user

Apache Superset data query improperly discloses database schema information to low-privileged guest user

Sunlitapache-superset · apache-supersetEPSS 0.57%via OSV
CVE-2025-48912High
1y ago

Apache Superset: Improper authorization bypass on row level security via SQL Injection

Apache Superset: Improper authorization bypass on row level security via SQL Injection

Twilightapache-superset · apache-supersetEPSS 0.72%via OSV
CVE-2025-27696High· 8.8
1y ago

Apache Superset Allows Ownership Takeover

Apache Superset Allows Ownership Takeover

Twilightapache-superset · apache-supersetEPSS 1.2%via OSV
CVE-2024-55633Medium· 6.5
1y ago

Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access

Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access

Sunlitapache-superset · apache-supersetEPSS 2.8%via OSV
CVE-2024-53947Critical· 9.8
1y ago

Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions

Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions

Midnightapache-superset · apache-supersetEPSS 0.84%via OSV
CVE-2024-53949Medium· 6.5
1y ago

Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled

Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled

Sunlitapache-superset · apache-supersetEPSS 0.72%via OSV
CVE-2024-53948Medium· 5.3
1y ago

Apache Superset: Error verbosity exposes metadata in analytics databases

Apache Superset: Error verbosity exposes metadata in analytics databases

Sunlitapache-superset · apache-supersetEPSS 0.85%via OSV
CVE-2024-39887Medium· 4.3PoC
2y ago

Apache Superset vulnerable to improper SQL authorization

Apache Superset vulnerable to improper SQL authorization

Twilightapache-superset · apache-supersetEPSS 4.4%via OSV
CVE-2024-34693Medium· 6.8PoC
2y ago

Apache Superset server arbitrary file read

Apache Superset server arbitrary file read

Twilightapache-superset · apache-supersetEPSS 1.6%via OSV
CVE-2024-28148Medium· 4.3
2y ago

Apache Superset Incorrect Authorization vulnerability

Apache Superset Incorrect Authorization vulnerability

Sunlitapache-superset · apache-supersetEPSS 0.70%via OSV
CVE-2024-24779Medium· 5.0
2y ago

Apache Superset: Improper data authorization when creating a new dataset

Apache Superset: Improper data authorization when creating a new dataset

Sunlitapache-superset · apache-supersetEPSS 0.73%via OSV
CVE-2024-24772Medium· 4.3
2y ago

Apache Superset: Improper Neutralization of custom SQL on embedded context

Apache Superset: Improper Neutralization of custom SQL on embedded context

Sunlitapache-superset · apache-supersetEPSS 0.95%via OSV
CVE-2024-27315Medium· 4.3
2y ago

Apache Superset: Improper error handling on alerts

Apache Superset: Improper error handling on alerts

Sunlitapache-superset · apache-supersetEPSS 0.98%via OSV
CVE-2024-24773Medium· 4.9
2y ago

Apache Superset: Improper validation of SQL statements allows for unauthorized access to data

Apache Superset: Improper validation of SQL statements allows for unauthorized access to data

Sunlitapache-superset · apache-supersetEPSS 0.78%via OSV
CVE-2024-26016Medium· 4.3
2y ago

Apache Superset: Improper authorization validation on dashboards and charts import

Apache Superset: Improper authorization validation on dashboards and charts import

Sunlitapache-superset · apache-supersetEPSS 0.87%via OSV
CVE-2023-49736Medium· 6.5
2y ago

Apache Superset SQL injection vulnerability

Apache Superset SQL injection vulnerability

Sunlitapache-superset · apache-supersetEPSS 1.2%via OSV
CVE-2023-49734High· 7.7
2y ago

Apache Superset incorrect write permissions vulnerability

Apache Superset incorrect write permissions vulnerability

Twilightapache-superset · apache-supersetEPSS 0.95%via OSV
CVE-2023-46104Medium· 6.5
2y ago

Apache Superset uncontrolled resource consumption

Apache Superset uncontrolled resource consumption

Sunlitapache-superset · apache-supersetEPSS 1.7%via OSV
CVE-2023-42502Medium· 5.4
2y ago

Apache Superset Open Redirect vulnerability

Apache Superset Open Redirect vulnerability

Sunlitapache-superset · apache-supersetEPSS 0.83%via OSV
CVE-2023-42505Medium· 4.3
2y ago

Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2023-40610High· 7.3
2y ago

Apache Superset - Elevation of Privilege

Apache Superset - Elevation of Privilege

Twilightapache-superset · apache-supersetEPSS 1.3%via OSV
CVE-2023-42504Medium· 6.5
2y ago

Apache Superset Allocation of Resources Without Limits or Throttling vulnerability

Apache Superset Allocation of Resources Without Limits or Throttling vulnerability

Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
apache-superset vulnerabilities (CVEs) · VulnSea