CVEFinder.io

CVE-2026-8724

🔶 medium
🔍 Scan for this CVE
Summary

A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure.

CVSS Score
4.7
Medium
EPSS Score
0.0
Exploit Probability
Published Date
2026-05-17
First Seen: 2026-05-18
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 13.8% of all 326,604 vulnerabilities in our database.

#281,479
Below average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: May 18, 2026
🔍 Exploitation Status
Poc
Proof-of-concept available
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Partial
Limited system impact
🏆 Discovered By
xpp39 (VulDB User) (reporter) VulDB CNA Team (coordinator)
SSVC data provided by CISA
Last Modified 2026-05-19
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 4

https://github.com/xpp3901/CVE_APPLY/tree/main/V-D00...
Exploit Mitigation Third Party Advisory
https://vuldb.com/submit/804256
Third Party Advisory VDB Entry
https://vuldb.com/vuln/364315
Third Party Advisory VDB Entry
https://vuldb.com/vuln/364315/cti
Permissions Required VDB Entry

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-33082 ⛔ critical 9.8 0.0 DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerab... 2026-04-16
CVE-2026-33083 ⚠️ high 8.8 0.0 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... 2026-04-16
CVE-2026-33084 ⚠️ high 8.8 0.0 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... 2026-04-16
CVE-2026-33121 ⚠️ high 8.8 0.0 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... 2026-04-16
CVE-2026-33122 ⛔ critical 9.8 0.0 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... 2026-04-16
CVE-2026-33207 ⚠️ high 8.8 0.0 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... 2026-04-16
These CVEs affect the same products