Beekeeperstudio is a database administration and development tool whose vulnerability profile centers on its core product and reflects application-layer input-handling challenges such as improper output encoding, cross-site scripting, and OS command injection. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Beekeeperstudio over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26174CRITICAL A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload injected into the display fields. | Mar 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-43143CRITICAL A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error modal | Nov 21, 2022 | 9.6 | 29 | NO | NO |
CVE-2023-28394HIGH Beekeeper Studio versions prior to 3.9.9 allows a remote authenticated attacker to execute arbitrary JavaScript code with the privilege of the application on the PC where the affec | May 23, 2023 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Beekeeperstudio.
Media articles that mention a CVE ID that affects a product developed by Beekeeperstudio — matched by CVE ID, not by vendor name.