VulnSea

apache-superset has 52 CVEs on record between 2022 and 2026. The busiest recent month was February 2026 with 5. The median CVSS is 5.4 (medium), with 1 rated critical. 2% have been exploited in the wild, in line with the corpus average.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
5.4
Publish → KEV
—(1)
Last 90 days
0 prev 0

Products

  • apache-superset 52
52
Total CVEs
1
Critical
1
CISA KEV
1
Exploited

apache-superset vulnerabilities

CVEs affecting apache-superset, newest first. Open any entry for full detail, references, and exploit status.

52 CVEsRSS

CVE-2023-43701Medium· 4.3
2y ago

Apache Superset Cross-site Scripting vulnerability

Apache Superset Cross-site Scripting vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2023-42501Medium· 4.3
2y ago

Apache Superset has Incorrect Default Permissions

Apache Superset has Incorrect Default Permissions

▾ Sunlitapache-superset · apache-supersetEPSS 0.86%via OSV
CVE-2023-27523Medium· 5.0
3y ago

Apache Superset vulnerable to improper data authorization

Apache Superset vulnerable to improper data authorization

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2023-39265Medium· 6.5PoC
3y ago

Apache Superset Improper Input Validation vulnerability

Apache Superset Improper Input Validation vulnerability

▾ Twilightapache-superset · apache-supersetEPSS 86%via OSV
CVE-2023-37941Medium· 6.6PoC
3y ago

Apache Superset Deserialization of Untrusted Data vulnerability

Apache Superset Deserialization of Untrusted Data vulnerability

▾ Twilightapache-superset · apache-supersetEPSS 35%via OSV
CVE-2023-39264Medium· 4.3
3y ago

Apache Superset may expose internal traces on REST API endpoints

Apache Superset may expose internal traces on REST API endpoints

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVE-2023-27526Medium· 4.3
3y ago

Apache Superset users may incorrectly create resources using the import charts feature

Apache Superset users may incorrectly create resources using the import charts feature

▾ Sunlitapache-superset · apache-supersetEPSS 1.2%via OSV
CVE-2023-36387Medium· 5.4
3y ago

Apache Superset has improper default REST API permission for Gamma users

Apache Superset has improper default REST API permission for Gamma users

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVE-2023-32672Medium· 4.3
3y ago

Apache Superset has incorrect authorization check

Apache Superset has incorrect authorization check

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2023-36388Medium· 4.3
3y ago

Apache Superset Server Side Request Forgery vulnerability

Apache Superset Server Side Request Forgery vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVE-2023-25504Medium· 6.5
3y ago

Apache Superset Server-Side Request Forgery vulnerability

Apache Superset Server-Side Request Forgery vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 0.96%via OSV
CVE-2023-30776Medium· 6.5
3y ago

Apache Superset vulnerable to Exposure of Sensitive Information

Apache Superset vulnerable to Exposure of Sensitive Information

▾ Sunlitapache-superset · apache-supersetEPSS 2.1%via OSV
CVE-2023-27524High· 8.9CISA KEVPoC
3y ago

Apache superset missing check for default SECRET_KEY

Apache superset missing check for default SECRET_KEY

▾ Abyssalapache-superset · apache-supersetEPSS 97%via OSV
CVE-2023-27525Medium· 4.3
3y ago

Apache Superset vulnerable to Improper Authorization

Apache Superset vulnerable to Improper Authorization

▾ Sunlitapache-superset · apache-supersetEPSS 0.78%via OSV
CVE-2022-43720Medium· 5.4
3y ago

Apache Superset vulnerable to Injection

Apache Superset vulnerable to Injection

▾ Sunlitapache-superset · apache-supersetEPSS 1.3%via OSV
CVE-2022-43721Medium· 5.4
3y ago

Apache Superset Open Redirect vulnerability

Apache Superset Open Redirect vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2022-41703Medium· 5.4
3y ago

Apache Superset's SQL Alchemy connector vulnerable to SQL Injection

Apache Superset's SQL Alchemy connector vulnerable to SQL Injection

▾ Sunlitapache-superset · apache-supersetEPSS 1.2%via OSV
CVE-2022-43717Medium· 5.4
3y ago

Apache Superset vulnerable to Cross-site Scripting

Apache Superset vulnerable to Cross-site Scripting

▾ Sunlitapache-superset · apache-supersetEPSS 1.3%via OSV
CVE-2022-45438Medium· 5.3
3y ago

Apache Superset has Improper Access Control

Apache Superset has Improper Access Control

▾ Sunlitapache-superset · apache-supersetEPSS 1.2%via OSV
CVE-2022-43718Medium· 5.4
3y ago

Apache Superset is vulnerable to Cross-Site Scripting (XSS)

Apache Superset is vulnerable to Cross-Site Scripting (XSS)

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVE-2022-43719High· 8.8
3y ago

Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints

Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints

▾ Twilightapache-superset · apache-supersetEPSS 0.57%via OSV
CVE-2021-37839Medium· 4.3
4y ago

Apache Superset allows authenticated users to access metadata they have no permission to

Apache Superset allows authenticated users to access metadata they have no permission to

▾ Sunlitapache-superset · apache-supersetEPSS 1.4%via OSV
apache-superset vulnerabilities (CVEs) — page 2 · VulnSea