Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tableau

First CVE: Aug 26, 2019Active for: 7 yearsTotal CVEs: 22
56.0
VTI Score
TOP TARGET

Tableau maintains a focused but strategically prominent portfolio of business-intelligence and data-visualization products, including server, desktop, and reader applications deployed across enterprises for analytics and reporting. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and concentrate through weakness classes including server-side request forgery, authorization bypass, path traversal, and unrestricted file upload that reflect the data-access and file-handling demands of web-based analytics platforms. The exposure pattern recurs across Tableau Server and Desktop variants, making vendor advisories relevant to both centralized deployments and distributed client installations. Defenders should treat this vendor's security updates as part of the analytics infrastructure patch cycle and prioritize internet-facing server instances; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tableau over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 26, 2019
6 years ago
Most Recent CVE
Aug 22, 2025
336 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-15637HIGH
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tablea
Aug 26, 20198.143NOYES
CVE-2025-26496CRITICAL
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code
Aug 22, 20259.333NONO
CVE-2019-19719MEDIUM
Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.
Dec 11, 20196.132NONO
CVE-2022-22128CRITICAL
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only
Oct 17, 20229.830NONO
CVE-2020-6939CRITICAL
Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users. If exploited, this could allow a malicious user to configu
Nov 23, 20209.830NONO
CVE-2025-52449HIGH
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alternative Execution Due
Jul 25, 20258.528NONO
CVE-2025-52451HIGH
Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.Thi
Aug 22, 20258.527NONO
CVE-2025-52453HIGH
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing. This issue affects Tab
Jul 25, 20258.227NONO
CVE-2025-52452HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - duplicate-data-source modu
Jul 25, 20258.527NONO
CVE-2025-52448HIGH
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data
Jul 25, 20258.127NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
18%
68%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.5%)
Network18 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (13.6%)
Attack Complexity
Low20 (90.9%)
High2 (9.1%)
Unknown0 (0.0%)
User Interaction
None17 (77.3%)
Unknown0 (0.0%)
Required5 (22.7%)
Privileges Required
Low7 (31.8%)
High1 (4.5%)
None14 (63.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.5% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tableau.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tableau — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tableau's Products

View all 2 CNAs →

Top CWEs