Eng's vulnerability footprint, while concentrated in a small product portfolio, reaches a more prominent standing than its product count suggests, centered on the Knowage and SpagoBI business-intelligence and reporting platforms. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a notable tendency toward public exploit availability, reflecting the web-facing nature and data-access privileges of these analytics platforms. The exposure recurs through a durable pattern of application-layer weaknesses: cross-site scripting, authentication bypasses, code injection, path traversal, and injection flaws that are characteristic of complex web applications handling user input and file system operations. Defenders should prioritize patches for these platforms, particularly in internet-reachable deployments, given the combination of serious severity and the availability of exploit tooling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eng over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-6231HIGH SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script | Jan 10, 2020 | 8.8 | 36 | NO | YES |
CVE-2013-6234HIGH Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an execu | Nov 22, 2019 | 8.0 | 32 | NO | YES |
CVE-2025-59954CRITICAL Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using an unsafe org.apache.commons.jxp | Sep 30, 2025 | 9.8 | 31 | NO | NO |
CVE-2021-30213MEDIUM Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetServic | May 12, 2021 | 6.1 | 30 | NO | YES |
CVE-2019-13188CRITICAL In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application. | Sep 5, 2019 | 9.8 | 30 | NO | NO |
CVE-2024-54794CRITICAL The script input feature of SpagoBI 3.5.1 allows arbitrary code execution. | Jan 21, 2025 | 9.1 | 29 | NO | NO |
CVE-2021-30214MEDIUM Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter. | May 12, 2021 | 5.4 | 29 | NO | NO |
CVE-2021-30055HIGH A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' parameter when running a report. | Apr 5, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-13348HIGH In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases. | Aug 28, 2019 | 8.8 | 27 | NO | NO |
CVE-2024-57971CRITICAL DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning of a JNDI Name. | Feb 16, 2025 | 9.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eng.
Media articles that mention a CVE ID that affects a product developed by Eng — matched by CVE ID, not by vendor name.