Metabase is a self-hosted business intelligence and data visualization platform that runs within organizations' infrastructure and integrates deeply with their data warehouses and databases, creating a significant attack surface around data access and web-facing query interfaces. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability, reflecting the platform's appeal as a target for data exfiltration and lateral movement. The exposure concentrates exclusively in the Metabase product itself and recurs through weakness classes including sensitive-information disclosure, code injection, cross-site scripting, and server-side request forgery—patterns typical of web applications that broker authenticated access to backend data systems. Defenders should prioritize patching this vendor's releases, restrict network access to Metabase instances, and audit user permissions and query logs; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Metabase over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41277HIGH Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add | Nov 17, 2021 | 7.5 | 97 | YES | YES |
CVE-2023-38646CRITICAL Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentic | Jul 21, 2023 | 9.8 | 92 | NO | YES |
CVE-2026-59827HIGH Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, | Jul 9, 2026 | 8.8 | 41 | NO | NO |
CVE-2026-22805HIGH Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscriptions could be potentially imp | Jan 12, 2026 | 8.6 | 32 | NO | NO |
CVE-2023-32680CRITICAL Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with native query editing permissions t | May 18, 2023 | 9.6 | 29 | NO | NO |
CVE-2026-33725HIGH Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, auth | Mar 27, 2026 | 7.2 | 28 | NO | NO |
CVE-2023-37470CRITICAL Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vul | Aug 4, 2023 | 9.8 | 27 | NO | NO |
CVE-2022-39362HIGH Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, unsaved SQL queries are auto-executed, which could po | Oct 26, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-39361HIGH Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, H2 (Sample Database) could allow Remote Code Executio | Oct 26, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24854HIGH Metabase is an open source business intelligence and analytics application. SQLite has an FDW-like feature called `ATTACH DATABASE`, which allows connecting multiple SQLite databas | Apr 14, 2022 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Metabase.
Media articles that mention a CVE ID that affects a product developed by Metabase — matched by CVE ID, not by vendor name.