Sploitus

CVE-2026-55635

No indexed exploits for CVE-2026-55635 yet

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter values directly into generated SQL in Quota2SQLObj.getYWheres() without applying the SQL literal validation and escaping used by other filter paths, allowing an authenticated user who can create or modify chart definitions or submit chart data requests containing quota filters to inject SQL into queries executed against configured datasources. This issue is fixed in version 2.10.24.

Affected products
Dataease
Fix
Available
CVSS 4.0
8.7 HIGH
EPSS
0.3% (18th percentile)
Weakness
CWE-89
NVD status
Deferred
Published
2026-07-07
CVE-2026-55635 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-55635 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-55635 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.