OpenRefine is a data-cleaning and transformation application maintained for small-to-medium deployment across research, journalism, and data-governance workflows, presenting a focused but notably exposed product line. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes centered on path traversal, cross-site scripting, SQL injection, server-side request forgery, and related input-handling flaws that reflect the application's web-based architecture and file-system integration. Defenders should treat this vendor's advisories as high-priority for exposed instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openrefine over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41887CRITICAL OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execut | Sep 15, 2023 | 9.8 | 51 | NO | NO |
CVE-2024-47883CRITICAL The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected | Oct 24, 2024 | 9.1 | 26 | NO | NO |
CVE-2023-37476HIGH OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution in the context | Jul 17, 2023 | 7.8 | 25 | NO | NO |
CVE-2018-20157HIGH The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers to read arbitrary files. | Dec 15, 2018 | 7.5 | 25 | NO | NO |
CVE-2019-3580HIGH OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file. | Jan 3, 2019 | 7.5 | 24 | NO | NO |
CVE-2024-47881HIGH OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension | Oct 24, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-47879HIGH OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` command means | Oct 24, 2024 | 8.8 | 23 | NO | NO |
CVE-2018-19859MEDIUM OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive. | Dec 5, 2018 | 6.5 | 23 | NO | NO |
CVE-2024-23833HIGH OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=3.7.7) where an attacker may co | Feb 12, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-41886HIGH OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file read vulnerability allows any unauthenticated user to read a | Sep 15, 2023 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openrefine.
Media articles that mention a CVE ID that affects a product developed by Openrefine — matched by CVE ID, not by vendor name.