Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dataease

First CVE: Feb 8, 2022Active for: 4 yearsTotal CVEs: 72
65.0
VTI Score
TOP TARGET

Dataease is a business-intelligence and data-visualization platform whose vulnerability footprint, despite affecting a single core product, has been disproportionately prominent in the landscape. The vendor's vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, reflecting the exposure risks inherent to internet-facing analytics and reporting services that handle sensitive data. The recurring weaknesses—SQL injection, untrusted deserialization, cross-site scripting, and injection-class flaws—are characteristic of web application frameworks and data-processing pipelines that must handle complex user input and dynamically construct queries. Defenders deploying this platform should treat vulnerabilities as high-priority, prioritize internet-exposure controls, and monitor closely for exploitation activity; live exploitation rates and severity counts are shown alongside this summary.

FAUCET AI Generated
72
Total CVEs
More Total CVEs than 99% of tracked vendors
14.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dataease over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 2022
4 years ago
Most Recent CVE
May 17, 2026
68 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (72 CVEs).

72 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-49002CRITICAL
DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to
Jun 3, 20259.868NOYES
CVE-2025-49001CRITICAL
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any
Jun 3, 20259.852NOYES
CVE-2025-32966CRITICAL
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched
Apr 23, 20259.843NOYES
CVE-2024-30269MEDIUM
DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/
Apr 8, 20245.342NOYES
CVE-2024-56511CRITICAL
DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be b
Jan 10, 20259.839NONO
CVE-2025-57773CRITICAL
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack can be dire
Aug 25, 20259.838NONO
CVE-2024-47073CRITICAL
DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signatu
Nov 7, 20249.137NOYES
CVE-2025-57772CRITICAL
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JDBC RCE bypass in DataEase. If the JDBC URL meets criteria, t
Aug 25, 20259.836NONO
CVE-2025-58748CRITICAL
Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data source implementation (H2.java) does not verify that a provided
Sep 15, 20259.834NONO
CVE-2025-58046CRITICAL
Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala data source is vulnerable to remote code execution due to i
Sep 15, 20259.834NONO
View all 72 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products72 CVEs
18%
36%
46%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network72 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low71 (98.6%)
High1 (1.4%)
Unknown0 (0.0%)
User Interaction
None67 (93.1%)
Unknown0 (0.0%)
Required5 (6.9%)
Privileges Required
Low29 (40.3%)
High1 (1.4%)
None42 (58.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (72 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
6.9% of CVEs· 96th percentile
ExploitDB
1 CVE
1.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dataease.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dataease — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dataease's Products

View all 3 CNAs →

Top CWEs