Graphql Engine

Vendor:

First CVE: Jul 29, 2019 · Active for 6 years

7
Total CVEs
More Total CVEs than 83% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Graphql Engine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 2019
6 years ago
Most Recent CVE
Jan 21, 2026
184 days ago

CVE Severity & Scoring

Graphql Engine7 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (14.3%)
Network6 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None5 (71.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject c
Jan 21, 20269.832NONO
Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1,
Dec 8, 20228.828NONO
Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. A
Dec 22, 20257.524NONO
Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been discovered within Hasura GraphQL Engine prior to versions 1.3.4,
Mar 14, 20237.524NONO
graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT.
Jul 29, 20197.524NONO
Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg
Dec 22, 20255.520NONO
Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attac
Dec 22, 20255.319NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Graphql Engine

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.14.018.80.8%00
2.12.018.80.8%00
1.3.347.00.5%00
1.0.017.51.2%00