CVE security advisories and vulnerability history for superset by apache.
68
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
5
Public exploits
With known exploit
5.5
Avg CVSS
2018–2026
Last updated
Overview
apache superset has 68 published CVE records since 2018, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 5 have a known public exploit. The average CVSS base score across scored CVEs is 5.5.
This page aggregates every publicly disclosed vulnerability (CVE) affecting apache superset, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of apache superset's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical1
High8
Medium40
Low4
15 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of apache superset's CVEs is confirmed exploited in the wild.
Public exploits
5
5 of apache superset's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every apache superset version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about apache superset vulnerabilities.
How many CVEs does apache superset have?
apache superset has 68 published CVE records since 2018.
How many apache superset CVEs are in CISA KEV?
Yes — 1 of apache superset's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for apache superset vulnerabilities?
Yes — 5 of apache superset's CVEs have a known public exploit.
Which versions of apache superset are affected?
330 distinct apache superset versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in apache superset CVEs?
apache superset's CVEs most often map to these CWE weakness types: CWE-863 (Incorrect Authorization), CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')).
How many critical apache superset vulnerabilities are there?
apache superset has 1 critical and 8 high-severity CVEs.
What is the average severity of apache superset CVEs?
The average CVSS base score across apache superset's scored CVEs is 5.5.