dtale has 7 CVEs on record between 2023 and 2026. The median CVSS is 6.7 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.7
- Publish → KEV
- —
- Last 90 days
- 0 prev 1
Products
- dtale 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-27194HighD-Tale affected by Remote Code Execution through the /save-column-filter endpoint41CVE-2024-21642High· 7.5D-Tale server-side request forgery through Web uploads41CVE-2024-55890MediumD-Tale allows Remote Code Execution through the Custom Filter Input40CVE-2024-8862High· 7.3D-Tale Command Execution Vulnerability40CVE-2024-45595Medium· 6.1D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder34
dtale vulnerabilities
CVEs affecting dtale, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-35052MediumD-Tale: Remote Code Execution through redis/shelf storage
D-Tale: Remote Code Execution through redis/shelf storage
▾ Sunlitdtale · dtaleEPSS 0.62%via OSV
CVE-2026-27194HighD-Tale affected by Remote Code Execution through the /save-column-filter endpoint
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
▾ Twilightdtale · dtaleEPSS 0.73%via OSV
CVE-2024-55890MediumPoCD-Tale allows Remote Code Execution through the Custom Filter Input
D-Tale allows Remote Code Execution through the Custom Filter Input
▾ Twilightdtale · dtaleEPSS 2.4%via OSV
CVE-2024-8862High· 7.3D-Tale Command Execution Vulnerability
D-Tale Command Execution Vulnerability
▾ Twilightdtale · dtaleEPSS 1.3%via OSV
CVE-2024-45595Medium· 6.1D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
▾ Sunlitdtale · dtaleEPSS 0.78%via OSV
CVE-2024-21642High· 7.5D-Tale server-side request forgery through Web uploads
D-Tale server-side request forgery through Web uploads
▾ Twilightdtale · dtaleEPSS 0.71%via OSV
CVE-2023-46134Medium· 6.1dtale vulnerable to Remote Code Execution through the Custom Filter Input
dtale vulnerable to Remote Code Execution through the Custom Filter Input
▾ Sunlitdtale · dtaleEPSS 0.76%via OSV