All 64 CVE vulnerabilities found in Dataease, with AI-generated Chinese analysis, references, and POCs.
This page presents a comprehensive vulnerability aggregation report for DataEase, focusing on security weaknesses identified within the data visualization and analytics platform. The collection aggregates data from multiple trusted sources, including vendor advisories, public databases, and community disclosures, ensuring a broad and accurate view of the product's security landscape. The entries span a historical period starting from the early development phases of the software through to the most recent updates, covering both legacy and modern versions to provide context for ongoing maintenance and upgrade decisions. By reviewing this data, users can effectively track DataEase’s advisory history to stay informed about patches and mitigation strategies released by the developers. It also allows security professionals to understand specific weakness classes that frequently affect the application, helping them prioritize testing and hardening efforts based on actual exposure rather than theoretical risks. Furthermore, this resource serves as a lookup tool for the product’s vulnerability history, enabling teams to assess the impact of specific flaws on their environments and verify whether their current deployment is affected. The content is structured to facilitate quick analysis of trends, such as the frequency of issues in authentication, data access, or system integration components. This plain text overview supports informed decision-making for IT administrators and security analysts who need to maintain the integrity and confidentiality of their DataEase installations without wading through unstructured or redundant information.
Vendor: dataease
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-28437 | SQL injection vulnerability due to the keyword blacklist for defending against SQL injection will be bypassed CWE-89 | 9.8 | Critical | 2023-03-24 |
| CVE-2023-28435 | Dataease file upload interface does not verify permission or file type CWE-79 | 6.5 | Medium | 2023-03-24 |
| CVE-2023-25807 | DataEase dashboard has a stored XSS vulnerability CWE-79 | 7.2 | High | 2023-02-28 |
| CVE-2022-39312 | Dataease Mysql Data Source JDBC Connection Parameters Not Verified Leads to Deserialization Vulnerability CWE-20 | 9.8 | Critical | 2022-10-25 |
All 64 known CVE vulnerabilities affecting Dataease with full Chinese analysis, references, and POCs where available.