Yellowfin is a business intelligence and analytics platform where observed vulnerabilities center on its web application layer, specifically authorization-bypass and cross-site scripting weaknesses. These issues reflect common challenges in access-control design and input handling within web-facing reporting and dashboarding interfaces; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yellowfinbi over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-19586CRITICAL Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI. | Sep 14, 2022 | 9.0 | 29 | NO | NO |
CVE-2021-36389HIGH In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially craf | Oct 14, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-36388HIGH In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a special | Oct 14, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-36387MEDIUM In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the pag | Oct 14, 2021 | 5.4 | 20 | NO | NO |
CVE-2019-1010147MEDIUM Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality | Jul 26, 2019 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yellowfinbi.
Media articles that mention a CVE ID that affects a product developed by Yellowfinbi — matched by CVE ID, not by vendor name.