Known Vulnerabilities for Bi Server by Pentaho
Listed below are 3 of the newest known vulnerabilities associated with "Bi Server" by "Pentaho".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65598 json | n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authen... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65596 json | n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credent... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65594 json | n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was intr... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65593 json | n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints tha... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65318 json | Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthe... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-65317 json | Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middlewa... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-65315 json | Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-65057 json | Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the ... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-65056 json | mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network s... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-65051 json | Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that all... | Not Provided | 2026-07-21 | 2026-07-21 |