Superset
Vendor:
First CVE: Nov 7, 2018 · Active for 7 years
68
Total CVEs
More Total CVEs than 98% of tracked products
7.6
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
1.5%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Superset over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 7, 2018
7 years ago
Most Recent CVE
Feb 24, 2026
150 days ago
CVE Severity & Scoring
Superset68 CVEs
82%
10%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network68 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low66 (97.1%)
High2 (2.9%)
Unknown0 (0.0%)
User Interaction
None57 (83.8%)
Unknown0 (0.0%)
Required11 (16.2%)
Privileges Required
Low55 (80.9%)
High1 (1.5%)
None12 (17.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (68 CVEs).
68 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27524CRITICAL Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation in | Apr 24, 2023 | 9.8 | 99 | YES | YES |
CVE-2023-39265MEDIUM Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database im | Sep 6, 2023 | 6.5 | 78 | NO | YES |
CVE-2018-8021CRITICAL Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released | Nov 7, 2018 | 9.8 | 73 | NO | YES |
CVE-2021-27907MEDIUM Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, | Mar 5, 2021 | 5.4 | 64 | NO | NO |
CVE-2021-28125MEDIUM Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener funct | Apr 27, 2021 | 6.1 | 52 | NO | NO |
CVE-2023-37941MEDIUM If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Supers | Sep 6, 2023 | 6.6 | 49 | NO | YES |
CVE-2024-39887CRITICAL An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions ar | Jul 16, 2024 | 9.8 | 40 | NO | YES |
CVE-2021-44451MEDIUM Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way | Feb 1, 2022 | 6.5 | 35 | NO | YES |
CVE-2022-27479CRITICAL Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue. | Apr 13, 2022 | 9.8 | 32 | NO | NO |
CVE-2024-53947CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not check | Dec 9, 2024 | 9.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (68 CVEs).
CISA KEV
1 CVE
1.5% of CVEs· 96th percentile
Metasploit
3 CVEs
4.4% of CVEs· 96th percentile
Nuclei
3 CVEs
4.4% of CVEs· 97th percentile
ExploitDB
2 CVEs
2.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (68 CVEs).
Media Mentions
Signals from CVEs in this product scope (68 CVEs).
Top CNAs Publishing CVEs For Superset
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.0 | 7 | 5.9 | 1.1% | 0 | 0 |
| 0.35.1 | 1 | 6.5 | 1.4% | 0 | 0 |
| 0.35.0 | 1 | 6.5 | 1.4% | 0 | 0 |
| 0.34.1 | 1 | 6.5 | 1.4% | 0 | 0 |
| 0.34.0 | 1 | 6.5 | 1.4% | 0 | 0 |