| Feb 24 | Apache Superset Improper Authorization allows low-privileged users to bypass access controls CVE-2026-23982Highfixed in 6.0.0 | High | 6.0.0 |
| Feb 24 | Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine CVE-2026-23969Mediumfixed in 4.1.2 | Medium | 4.1.2 |
| Feb 24 | Apache Superset allows privileged users to conduct error-based SQL Injection CVE-2026-23980Mediumfixed in 6.0.0 | Medium | 6.0.0 |
| Feb 24 | Apache Superset allows authenticated users to view sensitive data without explicit permissions CVE-2026-23983Lowfixed in 6.0.0 | Low | 6.0.0 |
| Feb 24 | Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections CVE-2026-23984Highfixed in 6.0.0 | High | 6.0.0 |
| Aug 142025 | Apache Superset data query improperly discloses database schema information to low-privileged guest user CVE-2025-55673Mediumfixed in 4.1.3.post1 | Medium | 4.1.3.post1 |
| Aug 142025 | Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability CVE-2025-55672Mediumfixed in 5.0.0 | Medium | 5.0.0 |
| Aug 142025 | Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions CVE-2025-55674Mediumfixed in 5.0.0 | Medium | 5.0.0 |
| Aug 142025 | Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access CVE-2025-55675Mediumfixed in 5.0.0 | Medium | 5.0.0 |
| May 302025 | Apache Superset: Improper authorization bypass on row level security via SQL Injection CVE-2025-48912Highfixed in 4.1.2 | High | 4.1.2 |
| May 132025 | Apache Superset Allows Ownership Takeover CVE-2025-27696Medium8.8fixed in 4.1.2 | Medium8.8 | 4.1.2 |
| Dec 122024 | Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access CVE-2024-55633High6.5fixed in 4.1.0 | High6.5 | 4.1.0 |
| Dec 92024 | Apache Superset: Error verbosity exposes metadata in analytics databases CVE-2024-53948Medium5.3fixed in 4.1.0 | Medium5.3 | 4.1.0 |
| Dec 92024 | Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled CVE-2024-53949High6.5fixed in 4.1.0 | High6.5 | 4.1.0 |
| Dec 92024 | Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions CVE-2024-53947Low9.8fixed in 4.1.0 | Low9.8 | 4.1.0 |
| Jul 162024 | Apache Superset vulnerable to improper SQL authorization CVE-2024-39887Medium4.3fixed in 4.0.2 | Medium4.3 | 4.0.2 |
| Jun 202024 | Apache Superset server arbitrary file read CVE-2024-34693Medium6.8fixed in 3.1.3, 4.0.1 | Medium6.8 | 3.1.3, 4.0.1 |
| May 72024 | Apache Superset Incorrect Authorization vulnerability CVE-2024-28148Medium4.3fixed in 3.1.2 | Medium4.3 | 3.1.2 |
| Feb 282024 | Apache Superset: Improper authorization validation on dashboards and charts import CVE-2024-26016Medium4.3fixed in 3.0.4, 3.1.1 | Medium4.3 | 3.0.4, 3.1.1 |
| Feb 282024 | Apache Superset: Improper data authorization when creating a new dataset CVE-2024-24779Medium5.0fixed in 3.0.4, 3.1.1 | Medium5.0 | 3.0.4, 3.1.1 |
| Feb 282024 | Apache Superset: Improper validation of SQL statements allows for unauthorized access to data CVE-2024-24773Medium4.9fixed in 3.0.4, 3.1.1 | Medium4.9 | 3.0.4, 3.1.1 |
| Feb 282024 | Apache Superset: Improper Neutralization of custom SQL on embedded context CVE-2024-24772Medium4.3fixed in 3.0.4, 3.1.1 | Medium4.3 | 3.0.4, 3.1.1 |
| Feb 282024 | Apache Superset: Improper error handling on alerts CVE-2024-27315Medium4.3fixed in 3.0.4, 3.1.1 | Medium4.3 | 3.0.4, 3.1.1 |
| Jan 232024 | Cross-site Scripting in Apache superset CVE-2023-49657Critical9.6fixed in 3.0.3 | Critical9.6 | 3.0.3 |
| Dec 192023 | Apache Superset uncontrolled resource consumption CVE-2023-46104Medium6.5fixed in 2.1.2, 3.1.0rc1 | Medium6.5 | 2.1.2, 3.1.0rc1 |
| Dec 192023 | Apache Superset incorrect write permissions vulnerability CVE-2023-49734High7.7fixed in 2.1.3, 3.0.2 | High7.7 | 2.1.3, 3.0.2 |
| Dec 192023 | Apache Superset SQL injection vulnerability CVE-2023-49736Medium6.5fixed in 2.1.3, 3.0.2 | Medium6.5 | 2.1.3, 3.0.2 |
| Nov 282023 | Apache Superset - Elevation of Privilege CVE-2023-40610High7.3fixed in 2.1.2 | High7.3 | 2.1.2 |
| Nov 282023 | Apache Superset Allocation of Resources Without Limits or Throttling vulnerability CVE-2023-42504Medium6.5fixed in 3.0.0 | Medium6.5 | 3.0.0 |
| Nov 282023 | Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability CVE-2023-42505Medium4.3fixed in 3.0.0 | Medium4.3 | 3.0.0 |
| Nov 282023 | Apache Superset Open Redirect vulnerability CVE-2023-42502Medium5.4fixed in 3.0.0 | Medium5.4 | 3.0.0 |
| Nov 272023 | Apache Superset has Incorrect Default Permissions CVE-2023-42501Medium4.3fixed in 2.1.2 | Medium4.3 | 2.1.2 |
| Nov 272023 | Apache Superset Cross-site Scripting vulnerability CVE-2023-43701Medium4.3fixed in 2.1.2 | Medium4.3 | 2.1.2 |
| Sep 62023 | Apache Superset has incorrect authorization check CVE-2023-32672Medium4.3no fix yet | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset Deserialization of Untrusted Data vulnerability CVE-2023-37941Medium6.6fixed in 2.1.1 | Medium6.6 | 2.1.1 |
| Sep 62023 | Apache Superset Improper Input Validation vulnerability CVE-2023-39265Medium6.5no fix yet | Medium6.5 | No fix yet |
| Sep 62023 | Apache Superset Server Side Request Forgery vulnerability CVE-2023-36388Medium4.3no fix yet | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset has improper default REST API permission for Gamma users CVE-2023-36387Medium5.4no fix yet | Medium5.4 | No fix yet |
| Sep 62023 | Apache Superset users may incorrectly create resources using the import charts feature CVE-2023-27526Medium4.3no fix yet | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset may expose internal traces on REST API endpoints CVE-2023-39264Medium4.3no fix yet | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset vulnerable to improper data authorization CVE-2023-27523Medium5.0no fix yet | Medium5.0 | No fix yet |
| Jul 62023 | Apache Superset vulnerable to Exposure of Sensitive Information CVE-2023-30776Medium6.5fixed in 2.1.0 | Medium6.5 | 2.1.0 |
| Jul 62023 | Apache Superset Server-Side Request Forgery vulnerability CVE-2023-25504Medium6.5fixed in 2.1.0 | Medium6.5 | 2.1.0 |
| Apr 242023 | Apache superset missing check for default SECRET_KEY CVE-2023-27524High8.9fixed in 2.1.0 | High8.9 | 2.1.0 |
| Apr 172023 | Apache Superset vulnerable to Improper Authorization CVE-2023-27525Medium4.3no fix yet | Medium4.3 | No fix yet |
| Jan 162023 | Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints CVE-2022-43719High8.8no fix yet | High8.8 | No fix yet |
| Jan 162023 | Apache Superset is vulnerable to Cross-Site Scripting (XSS) CVE-2022-43718Medium5.4no fix yet | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset vulnerable to Cross-site Scripting CVE-2022-43717Medium5.4no fix yet | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset's SQL Alchemy connector vulnerable to SQL Injection CVE-2022-41703Medium5.4no fix yet | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset has Improper Access Control CVE-2022-45438Medium5.3no fix yet | Medium5.3 | No fix yet |
| Jan 162023 | Apache Superset Open Redirect vulnerability CVE-2022-43721Medium5.4no fix yet | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset vulnerable to Injection CVE-2022-43720Medium5.4no fix yet | Medium5.4 | No fix yet |
| Jul 72022 | Apache Superset allows authenticated users to access metadata they have no permission to CVE-2021-37839Medium4.3fixed in 1.5.1 | Medium4.3 | 1.5.1 |
| May 242022 | Apache Superset Stored XSS on Dashboard markdown CVE-2021-27907Medium5.4fixed in 0.38.1 | Medium5.4 | 0.38.1 |
| May 242022 | Apache Superset OS Command Injection CVE-2020-13948High8.8fixed in 0.37.1 | High8.8 | 0.37.1 |
| May 242022 | Improper Encoding or Escaping of Output in Apache Superset CVE-2021-42250High6.5fixed in 1.3.2 | High6.5 | 1.3.2 |
| May 242022 | Apache Superset allowed for database connections password leak for authenticated users CVE-2021-41972High6.5fixed in 1.3.2 | High6.5 | 1.3.2 |
| May 242022 | Apache Superset Cross-site Scripting (XSS) vulnerability on the Explore page CVE-2021-32609Medium5.4fixed in 1.2.0 | Medium5.4 | 1.2.0 |
| May 242022 | Apache Superset SQL Injection when template processing is enabled CVE-2021-41971High8.8fixed in 1.3.1 | High8.8 | 1.3.1 |
| Apr 142022 | SQL injection in apache-superset CVE-2022-27479Critical9.8fixed in 1.4.2 | Critical9.8 | 1.4.2 |