Power Bi Report Server

Vendor:

First CVE: Dec 10, 2019 · Active for 6 years

10
Total CVEs
More Total CVEs than 88% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Power Bi Report Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 10, 2019
6 years ago
Most Recent CVE
Jul 14, 2026
13 days ago

CVE Severity & Scoring

Power Bi Report Server10 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (30.0%)
Unknown0 (0.0%)
Required7 (70.0%)
Privileges Required
Low6 (60.0%)
High0 (0.0%)
None4 (40.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
Jul 14, 20268.034NONO
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the se
Nov 10, 20219.629NONO
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Feb 10, 20268.828NONO
Power BI Remote Code Execution Vulnerability
Jul 14, 20218.828NONO
Power BI Report Server Spoofing Vulnerability
Oct 8, 20248.825NONO
Power BI Report Server Spoofing Vulnerability
Feb 14, 20238.225NONO
Microsoft Power BI Information Disclosure Vulnerability
Mar 11, 20217.724NONO
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS
Dec 10, 20196.123NONO
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing
May 21, 20206.818NONO
Power BI Report Server Spoofing Vulnerability
Oct 8, 20244.717NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Power Bi Report Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
15.0.1107.16519.60.6%00
15.0.1104.30017.72.8%00
15.0.1103.23417.72.8%00