Pinterest's disclosed vulnerabilities center on Querybook, an internally developed data-exploration and query-management platform, with the recurring signal rooted in web-application input-handling issues including cross-site scripting and insufficient data-authenticity verification. Treat this as a compact vendor profile reflecting a narrowly scoped disclosure footprint; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pinterest over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46151MEDIUM Querybook is an open source data querying UI. In affected versions user provided data is not escaped in the error field of the auth callback url in `querybook/server/app/auth/oauth | Dec 6, 2022 | 6.1 | 22 | NO | NO |
CVE-2024-28251HIGH Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's datadocs functionality works by using a Websocket Server. The | Mar 14, 2024 | 7.3 | 19 | NO | NO |
CVE-2024-27103MEDIUM Querybook is a Big Data Querying UI. When a user searches for their queries, datadocs, tables and lists, the search result is marked and highlighted, and this feature uses dangerou | Feb 28, 2024 | 6.1 | 17 | NO | NO |
CVE-2024-26148MEDIUM Querybook is a user interface for querying big data. Prior to version 3.31.1, there is a vulnerability in Querybook's rich text editor that enables users to input arbitrary URLs wi | Feb 21, 2024 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pinterest.
Media articles that mention a CVE ID that affects a product developed by Pinterest — matched by CVE ID, not by vendor name.