Datagear develops a data visualization and analytics platform whose vulnerability profile, despite a narrow product scope, ranks notably in the vulnerability landscape. Vulnerabilities affecting the product skew strongly toward critical-severity outcomes and recur across a consistent set of weaknesses centered on input handling and data processing: cross-site scripting, injection, SQL injection, untrusted deserialization, and path traversal all reflect the parser and query-execution demands of a web-based analytics engine. Defenders deploying this product should prioritize patch cycles for these input-validation and deserialization classes; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Datagear over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1571CRITICAL A vulnerability, which was classified as critical, was found in DataGear up to 4.5.0. This affects an unknown part of the file /analysisProject/pagingQueryData. The manipulation of | Mar 22, 2023 | 9.8 | 29 | NO | NO |
CVE-2025-65792CRITICAL DataGear v5.5.0 is vulnerable to Arbitrary File Deletion. | Dec 10, 2025 | 9.1 | 28 | NO | NO |
CVE-2023-7299CRITICAL A vulnerability was found in DataGear up to 4.60. It has been declared as critical. This vulnerability affects unknown code of the file /dataSet/resolveSql. The manipulation of the | Nov 23, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-37759CRITICAL DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Viewing interface. | Jun 24, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-7552HIGH A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file Conversio | Aug 6, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-2042HIGH A vulnerability, which was classified as problematic, has been found in DataGear up to 4.7.0/5.1.0. Affected by this issue is some unknown functionality of the component JDBC Serve | Apr 14, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-1573MEDIUM A vulnerability was found in DataGear up to 1.11.1 and classified as problematic. This issue affects some unknown processing of the component Graph Dataset Handler. The manipulatio | Mar 22, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-1572MEDIUM A vulnerability has been found in DataGear up to 1.11.1 and classified as problematic. This vulnerability affects unknown code of the component Plugin Handler. The manipulation lea | Mar 22, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-1772MEDIUM A vulnerability was found in DataGear up to 4.5.1. It has been classified as problematic. This affects an unknown part of the component Diagram Type Handler. The manipulation leads | Mar 31, 2023 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Datagear.
Media articles that mention a CVE ID that affects a product developed by Datagear — matched by CVE ID, not by vendor name.