These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-50124 is a high-severity vulnerability in DataEase, an open-source data visualization tool. The issue allows for arbitrary code execution via a crafted payload uploaded through the Excel upload API. This vulnerability was fixed in version 2.10.23. Affected users should apply the patch immediately. The vulnerability arises from insufficient validation of uploaded files and improper use of the zip: [truncated]
CVE-2026-50030 is a high-severity SQL injection vulnerability in DataEase, a data visualization and analysis tool. The vulnerability allows attackers to query arbitrary readable datasource tables and return them in preview responses. This issue was fixed in version 2.10.23. Affected users should apply the patch to prevent exploitation. The vulnerability exists in the DataEase SQL preview feature, which ex [truncated]
CVE-2026-49867 is a stored cross-site scripting vulnerability in DataEase, an open-source data visualization and analysis tool. Prior to version 2.10.23, authenticated users can submit template static resources through POST /de2api/templateManage/save or DataVisualizationServer.decompression. The StaticResourceServer.saveFilesToServe and StaticResourceServer.saveSingleFileToServe methods write Base64-deco [truncated]
CVE-2026-46684 is a critical vulnerability in DataEase, an open-source data visualization and analysis tool. The issue allows forged tokens to be accepted due to insufficient verification in the token handling process. Affected product deployments should be identified and owners assigned for follow-up. The vulnerability class is related to token handling and verification. Likely operational impact include [truncated]
CVE-2026-45535 is a SQL injection vulnerability in DataEase, an open-source data visualization and analysis tool. The vulnerability exists in DataEase SQL-type datasets, where attacker-controlled SQL variable defaultValue entries, such as ${var}, are stored. When a user with dataset read permission accesses the dataset, the SqlparserUtils.handleVariableDefaultValue() function inserts these entries using S [truncated]
CVE-2026-45534 is a critical remote code execution vulnerability in DataEase Redshift datasource connections prior to version 2.10.23. The issue arises from the loading of attacker-controlled rsjdbc.ini configuration from System.getProperty('java.io.tmpdir'), which can lead to the execution of a reflection-based remote code execution chain during a normal JDBC connection. This vulnerability has a CVSS sco [truncated]
CVE-2026-45419 is a high-severity vulnerability in DataEase, an open-source data visualization and analysis tool. The vulnerability allows for path traversal and arbitrary file writes due to insufficient validation of staticResource names and Base64 content in template saves. Affected product deployments should be identified and owners assigned for follow-up. Official advisories and CVE records should be [truncated]
CVE-2026-45417 is a SQL injection vulnerability in DataEase, a data visualization and analysis tool. The vulnerability exists in versions prior to 2.10.23 and allows attackers to inject malicious SQL code, potentially leading to data breaches or system compromise. This issue has been fixed in version 2.10.23. Users of affected versions should apply the patch to prevent SQL injection attacks. The vulnerabi [truncated]
CVE-2026-57172 is a high-severity vulnerability in DataEase, an open-source data visualization tool. The issue allows attackers to forge linkToken JWTs and gain unauthorized access to backend resources. This vulnerability exists in the ShareSecretManage component of DataEase, where a hardcoded default share link signature key is used. The vulnerability allows an attacker who can obtain a passwordless shar [truncated]
CVE-2026-55647 is a medium severity vulnerability in DataEase, an open source data visualization and analysis tool. Prior to version 2.10.24, dashboard text components render stored component content with Vue v-html without server-side HTML sanitization, allowing an authenticated user who can edit dashboard component data to inject HTML with executable event handlers that execute when another user or shar [truncated]
CVE-2026-55635 is a SQL injection vulnerability in DataEase, an open-source data visualization and analysis tool. Prior to version 2.10.24, the tool embeds attacker-controlled filter values directly into generated SQL in Quota2SQLObj.getYWheres() without applying SQL literal validation and escaping. This allows an authenticated user who can create or modify chart definitions or submit chart data requests [truncated]
CVE-2026-55633 is a remote code execution vulnerability in DataEase, an open-source data visualization and analysis tool. The vulnerability allows an authenticated attacker to upload a zip archive disguised with a .ttf extension and then exploit it through the zip protocol to achieve remote code execution. This issue was fixed in version 2.10.24. The vulnerability exists due to a bypass of the H2 zip prot [truncated]
CVE-2026-55631 is a HIGH severity vulnerability in DataEase open source data visualization and analysis tool, affecting its font management module. The vulnerability has a CVSS score of 7.2 and allows authenticated users to delete arbitrary writable files. Users should review the official CVE record and apply patches to prevent exploitation. The issue is fixed in version 2.10.24. Defenders should verify a [truncated]
CVE-2026-53751 is a HIGH severity vulnerability in DataEase, an open source data visualization and analysis tool. The vulnerability exists in the H2 database JDBC URL validation logic, which can be bypassed with special Unicode characters, allowing attackers to achieve arbitrary code execution. This issue is fixed in version 2.10.24. Affected product deployments should be reviewed, and owners should be as [truncated]
CVE-2026-53729 is a high-severity vulnerability in DataEase, an open-source data visualization tool. Prior to version 2.10.24, the tool allowed any user to view, delete, retry, or generate download links for export tasks belonging to other users. The /exportCenter/download/{id} endpoint was whitelisted from authentication, allowing unauthenticated access to exported files. This vulnerability has a high im [truncated]
CVE-2026-50530 affects DataEase, an open source data visualization and analysis tool, through a vulnerability in its share mode chart data interface. The vulnerability allows unauthorized data retrieval by validating only the sceneId match with the resourceId in the link token, failing to validate tableId and field IDs in the request body. This issue is fixed in version 2.10.24. Users should apply patches [truncated]
CVE-2026-50529 is a vulnerability in DataEase, an open source data visualization and analysis tool. Prior to version 2.10.24, the /de2api/share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN before validating the share password or ticket. This allows unauthenticated attackers who know a protected share UUID to obtain a valid link token for subsequent share-related API calls even with miss [truncated]
CVE-2026-8724 describes a SQL injection flaw affecting Dataease 2.10.20 in the Data Dashboard component, specifically the SqlparserUtils.transFilter function in SqlparserUtils.java. The issue is described as remotely reachable and the supplied record says public exploit material has been released. The published CVSS information is low overall, but the combination of SQL injection, remote reachability, and [truncated]
A server-side request forgery vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of the file backend/apps/db/es_engine.py of the component Elasticsearch Handler. The manipulation of the argument address causes server-side request forgery. The attack may be initiated remotely. Upgrading to version 1.7.0 is capable of addressing this issue. The v [truncated]