Dataease is a business-intelligence and data-visualization platform whose vulnerability footprint, despite affecting a single core product, has been disproportionately prominent in the landscape. The vendor's vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, reflecting the exposure risks inherent to internet-facing analytics and reporting services that handle sensitive data. The recurring weaknesses—SQL injection, untrusted deserialization, cross-site scripting, and injection-class flaws—are characteristic of web application frameworks and data-processing pipelines that must handle complex user input and dynamically construct queries. Defenders deploying this platform should treat vulnerabilities as high-priority, prioritize internet-exposure controls, and monitor closely for exploitation activity; live exploitation rates and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dataease over time
Signals from CVEs in this vendor scope (72 CVEs).
72 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-49002CRITICAL DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to | Jun 3, 2025 | 9.8 | 68 | NO | YES |
CVE-2025-49001CRITICAL DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any | Jun 3, 2025 | 9.8 | 52 | NO | YES |
CVE-2025-32966CRITICAL DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched | Apr 23, 2025 | 9.8 | 43 | NO | YES |
CVE-2024-30269MEDIUM DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/ | Apr 8, 2024 | 5.3 | 42 | NO | YES |
CVE-2024-56511CRITICAL DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be b | Jan 10, 2025 | 9.8 | 39 | NO | NO |
CVE-2025-57773CRITICAL DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack can be dire | Aug 25, 2025 | 9.8 | 38 | NO | NO |
CVE-2024-47073CRITICAL DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signatu | Nov 7, 2024 | 9.1 | 37 | NO | YES |
CVE-2025-57772CRITICAL DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JDBC RCE bypass in DataEase. If the JDBC URL meets criteria, t | Aug 25, 2025 | 9.8 | 36 | NO | NO |
CVE-2025-58748CRITICAL Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data source implementation (H2.java) does not verify that a provided | Sep 15, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-58046CRITICAL Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala data source is vulnerable to remote code execution due to i | Sep 15, 2025 | 9.8 | 34 | NO | NO |
Signals from CVEs in this vendor scope (72 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dataease.
Media articles that mention a CVE ID that affects a product developed by Dataease — matched by CVE ID, not by vendor name.