Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Metabase

First CVE: Nov 15, 2018Active for: 8 yearsTotal CVEs: 22
65.1
VTI Score
TOP TARGET

Metabase is a self-hosted business intelligence and data visualization platform that runs within organizations' infrastructure and integrates deeply with their data warehouses and databases, creating a significant attack surface around data access and web-facing query interfaces. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability, reflecting the platform's appeal as a target for data exfiltration and lateral movement. The exposure concentrates exclusively in the Metabase product itself and recurs through weakness classes including sensitive-information disclosure, code injection, cross-site scripting, and server-side request forgery—patterns typical of web applications that broker authenticated access to backend data systems. Defenders should prioritize patching this vendor's releases, restrict network access to Metabase instances, and audit user permissions and query logs; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
3.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
4.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Metabase over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 15, 2018
7 years ago
Most Recent CVE
Jul 9, 2026
15 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-41277HIGH
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add
Nov 17, 20217.597YESYES
CVE-2023-38646CRITICAL
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentic
Jul 21, 20239.892NOYES
CVE-2026-59827HIGH
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection,
Jul 9, 20268.841NONO
CVE-2026-22805HIGH
Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscriptions could be potentially imp
Jan 12, 20268.632NONO
CVE-2023-32680CRITICAL
Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with native query editing permissions t
May 18, 20239.629NONO
CVE-2026-33725HIGH
Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, auth
Mar 27, 20267.228NONO
CVE-2023-37470CRITICAL
Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vul
Aug 4, 20239.827NONO
CVE-2022-39362HIGH
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, unsaved SQL queries are auto-executed, which could po
Oct 26, 20228.827NONO
CVE-2022-39361HIGH
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, H2 (Sample Database) could allow Remote Code Executio
Oct 26, 20228.827NONO
CVE-2022-24854HIGH
Metabase is an open source business intelligence and analytics application. SQLite has an FDW-like feature called `ATTACH DATABASE`, which allows connecting multiple SQLite databas
Apr 14, 20228.827NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
50%
36%
14%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (95.5%)
High1 (4.5%)
Unknown0 (0.0%)
User Interaction
None17 (77.3%)
Unknown0 (0.0%)
Required5 (22.7%)
Privileges Required
Low14 (63.6%)
High1 (4.5%)
None7 (31.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
1 CVE
4.5% of CVEs· 99th percentile
Metasploit
1 CVE
4.5% of CVEs· 98th percentile
Nuclei
2 CVEs
9.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Metabase.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Metabase — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Metabase's Products

View all 5 CNAs →

Top CWEs