Known CVE
Metabase - Unauthenticated SQL Injection
Metabase contains a sql injection caused by improper sanitization of input in the '/reset_password' database endpoint, letting remote unauthenticated attackers gain administrator access, exploit requires no special privileges.
CVE-2026-72898
Critical2026CVSS 10CWE-89
cve2026 · sqli · metabase · unauth · rce · kev · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website