Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-1378
  • PyPI/flask-appbuilder
Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods 07 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-1379
  • PyPI/flask-appbuilder
Flask-AppBuilder open redirect vulnerability using HTTP host injection 07 Jul
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-1382
  • PyPI/flask-appbuilder
Flask-AppBuilder's login form allows browser to cache sensitive fields 07 Jul
  • Fix available
  • Severity - 4.8 (Medium)
PYSEC-2026-1381
  • PyPI/flask-appbuilder
Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS) 07 Jul
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-1380
  • PyPI/flask-appbuilder
Flask-AppBuilder Has No Rate Limiting on Login AUTH DB 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-635
  • PyPI/flask-appbuilder
Open Redirect in Flask-AppBuilder 02 Jul
  • Fix available
  • Severity - 6.1 (Medium)
PYSEC-2026-340
  • PyPI/flask-appbuilder
Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID 29 Jun
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-765j-9r45-w2q2
  • PyPI/flask-appbuilder
Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods 11 Sep 2025
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-99pm-ch96-ccp2
  • PyPI/flask-appbuilder
Flask-AppBuilder open redirect vulnerability using HTTP host injection 16 May 2025
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2025-15
  • PyPI/flask-appbuilder
See record for full details 03 Mar 2025
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-p8q5-cvwx-wvwp
  • PyPI/flask-appbuilder
Flask-AppBuilder Observable Response Discrepancy 03 Mar 2025
  • Fix available
  • Severity - 3.7 (Low)
GHSA-fw5r-6m3x-rh7p
  • PyPI/flask-appbuilder
Flask-AppBuilder's login form allows browser to cache sensitive fields 04 Sep 2024
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-j2pw-vp55-fqqj
  • PyPI/flask-appbuilder
Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID 28 Feb 2024
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-fqxj-46wg-9v84
  • PyPI/flask-appbuilder
Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS) 28 Feb 2024
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2023-94
  • PyPI/flask-appbuilder
  • github.com/dpgaspar/Flask-AppBuilder
See record for full details 22 Jun 2023
  • Fix available
GHSA-jhpr-j7cq-3jp3
  • PyPI/flask-appbuilder
Flask-AppBuilder vulnerable to possible disclosure of sensitive information on user error 22 Jun 2023
  • Fix available
  • Severity - 5.1 (Medium)