Spagobi
Vendor:
First CVE: Mar 9, 2014 · Active for 12 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spagobi over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 9, 2014
12 years ago
Most Recent CVE
Jan 21, 2025
551 days ago
CVE Severity & Scoring
Spagobi8 CVEs
13%
50%
25%
13%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (62.5%)
Unknown3 (37.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (62.5%)
High0 (0.0%)
Unknown3 (37.5%)
User Interaction
None2 (25.0%)
Unknown3 (37.5%)
Required3 (37.5%)
Privileges Required
Low3 (37.5%)
High1 (12.5%)
None1 (12.5%)
Unknown3 (37.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-6231HIGH SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script | Jan 10, 2020 | 8.8 | 36 | NO | YES |
CVE-2013-6234HIGH Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an execu | Nov 22, 2019 | 8.0 | 32 | NO | YES |
CVE-2024-54794CRITICAL The script input feature of SpagoBI 3.5.1 allows arbitrary code execution. | Jan 21, 2025 | 9.1 | 29 | NO | NO |
CVE-2013-6233MEDIUM Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short docu | Mar 9, 2014 | 4.3 | 22 | NO | YES |
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page. | Mar 9, 2014 | 3.5 | 20 | NO | YES |
CVE-2024-54795MEDIUM SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function. | Jan 21, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-54792MEDIUM A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwa | Jan 21, 2025 | 6.1 | 18 | NO | NO |
CVE-2014-7296MEDIUM The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java cod | Oct 8, 2014 | 6.8 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
50.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Spagobi
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0 | 1 | 6.8 | 1.7% | 0 | 0 |
| 3.5.1 | 3 | 6.9 | 4.5% | 0 | 0 |