Spagobi

Vendor:

First CVE: Mar 9, 2014 · Active for 12 years

8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Spagobi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 9, 2014
12 years ago
Most Recent CVE
Jan 21, 2025
551 days ago

CVE Severity & Scoring

Spagobi8 CVEs
All CVEs352,713 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (62.5%)
Unknown3 (37.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (62.5%)
High0 (0.0%)
Unknown3 (37.5%)
User Interaction
None2 (25.0%)
Unknown3 (37.5%)
Required3 (37.5%)
Privileges Required
Low3 (37.5%)
High1 (12.5%)
None1 (12.5%)
Unknown3 (37.5%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
Jan 10, 20208.836NOYES
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an execu
Nov 22, 20198.032NOYES
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
Jan 21, 20259.129NONO
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short docu
Mar 9, 20144.322NOYES
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page.
Mar 9, 20143.520NOYES
SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.
Jan 21, 20255.418NONO
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwa
Jan 21, 20256.118NONO
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java cod
Oct 8, 20146.818NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
50.0% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Spagobi

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.016.81.7%00
3.5.136.94.5%00