Skip to content

Known CVE

Metabase - Unauthenticated SQL Injection

Metabase contains a sql injection caused by improper sanitization of input in the '/reset_password' database endpoint, letting remote unauthenticated attackers gain administrator access, exploit requires no special privileges.

CVE-2026-72898

Critical2026CVSS 10CWE-89

cve2026 · sqli · metabase · unauth · rce · kev · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website