Databasir is a database documentation and collaboration platform whose vulnerability surface centers on input-handling flaws in the primary product, including improper input validation, expression language injection, SQL injection, and server-side request forgery. These weaknesses reflect the product's role as a web-based tool that parses and processes database schemas and user input; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Databasir over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24860CRITICAL Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability. An attacker can use hard | Apr 20, 2022 | 9.8 | 32 | NO | NO |
CVE-2023-27821CRITICAL Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter. | Mar 28, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-24861HIGH Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code execution vulnerability. JDBC drivers are not validated prior to | Apr 20, 2022 | 8.8 | 30 | NO | NO |
CVE-2025-66944CRITICAL SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint | Mar 4, 2026 | 9.8 | 29 | NO | NO |
CVE-2022-31196HIGH Databasir is a database metadata management platform. Databasir <= 1.06 has Server-Side Request Forgery (SSRF) vulnerability. The SSRF is triggered by a sending a **single** HTTP P | Sep 2, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-24862HIGH Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Server-Side Request Forgery vulnerability. During the download verification | Apr 20, 2022 | 7.7 | 25 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Databasir.
Media articles that mention a CVE ID that affects a product developed by Databasir — matched by CVE ID, not by vendor name.