Depomo's vulnerability profile centers on Chartbrew, a modestly represented data-visualization and analytics platform. The vendor's disclosures skew toward serious severity outcomes and recur through access-control and input-handling weakness classes, including code injection, authorization bypass, improper access control, and cross-site scripting, that are characteristic of web-facing application tiers handling user data and query construction. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Depomo over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-30232CRITICAL Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartbrew allows authenticated users | Apr 10, 2026 | 9.6 | 34 | NO | NO |
CVE-2026-27005CRITICAL Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3, an unauthenticated attacker c | Mar 6, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-25888HIGH Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execut | Mar 6, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-32252HIGH Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.9.0, a cross-tenant authorization bypass e | Apr 10, 2026 | 7.7 | 27 | NO | NO |
CVE-2026-27603HIGH Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the chart filter endpoint POS | Mar 6, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-25887HIGH Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execut | Mar 6, 2026 | 7.2 | 26 | NO | NO |
CVE-2026-25877MEDIUM Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, the application performs auth | Mar 6, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-27605MEDIUM Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the application allows upload | Mar 6, 2026 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Depomo.
Media articles that mention a CVE ID that affects a product developed by Depomo — matched by CVE ID, not by vendor name.