Skip to main content

Vendor/product archive

dpgaspar / flask-appbuilder CVEs

Beta · best-effort

13 CVEs tagged to dpgaspar / flask-appbuilder1 Critical, 3 High, 6 Medium, 3 Low, 0 Unrated.

CVE-2025-58065

Published Sep 11, 2025

Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to use OAuth, LDAP, or other non-database authentication meth…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32962

Published May 16, 2025

Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated actor to perform an open redire…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24023

Published Mar 3, 2025

Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-45314

Published Sep 4, 2024

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. T…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-27083

Published Feb 29, 2024

Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacke…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25128

Published Feb 29, 2024

Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-29005

Published Apr 10, 2023

Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31177

Published Aug 1, 2022

Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-24776

Published Mar 24, 2022

Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database aut…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21659

Published Jan 31, 2022

Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnera…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41265

Published Dec 9, 2021

Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32805

Published Sep 8, 2021

Flask-AppBuilder is an application development framework, built on top of Flask. In affected versions if using Flask-AppBuilder OAuth, an attacker can share a carefully crafted UR…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29621

Published Jun 7, 2021

Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1