Vulnerability threat dossier

CVE-2025-49002

dataeasedataease

DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability has been fixed in v2.10.10. No known workarounds are available.

VTP deterministic threat10.1of 100 · CVSS excluded

VTP analyst assessment

DataEase patch bypass

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence88%
Public exploitation · VTP factUNKNOWN

Assessment

DataEase before 2.10.10 has a case-insensitive bypass for the prior CVE-2025-32966 patch.

Why it matters

  • The bypass may undermine protections intended by the earlier patch.

Evidence

0 record references and 0 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

No supplied evidence confirms public exploitation or VTP observation. EPSS is predictive context only.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Review in your environment: if you use DataEase, check versions before 2.10.10.

AI baseline history (1)
  1. BASELINE ASSESSED
    DataEase patch bypassgpt-5.6-terra · low
Technical severityHIGHCVSS 8.2 · technical context
Public exploitationUNKNOWNGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS0.5099th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.50; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

  1. 17:0505 May
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2025-49002.

05

Original publications

Source record

Nuclei Templates v10.4.3 - Release Notes

New Templates Added: 105 | CVEs Added: 62 | First-time contributions: 12 🔥 Release Highlights 🔥 [ CVE-2026-42167 ] ProFTPD mod_sql - Preauth User Backdoor ( @pussycat0x ) [high] 🔥 [ CVE-2026-41179 ] RClone RC - Command Injection ( @theamanrawat ) [critical] 🔥 [ CVE-2026-41176 ] Rclone RC - Broken Access Control ( @theamanrawat ) [critical] 🔥 [ CVE-2026-40466 ] Apache ActiveMQ - RCE via HTTP Discovery Transport Bypass ( @dhiyaneshdk ) [high] 🔥 [ CVE-2026-39808 ] Fortinet FortiSandbox - Command Injection ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-39363 ] Vite Dev Server - Arbitrary File Read ( @theamanrawat ) [high] 🔥 [ CVE-2026-35029 ] LiteLLM - Arbitrary File Read ( @theamanrawat ) [high] 🔥 [ CVE-2026-33626 ] LMDeploy - Server-Side Request Forgery ( @theamanrawat ) [high] (kev) (vKEV) 🔥 [ CVE-2026-33439 ] OpenAM <= 16.0.5 - Pre-Auth RCE via jato.clientSession Deserialization ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-33032 ] Nginx UI - Broken Access Control ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-33017 ] Langflow < 1.9.0 - Remote Code Execution ( @himind ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-27174 ] MajorDoMo - Unauthenticated RCE (@0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-24423 ] SmarterMail - Remote Code Execution ( @jyoti369 ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-4631 ] Cockpit Web Console < 360 - Remote Code Execution ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-3844 ] Breeze <= 2.4.4 - Arbitrary File Upload ( @theamanrawat , @ritikchaddha ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-13390 ] WP Directory Kit <= 1.4.4 - Authentication Bypass (@maxthepm) [critical] (kev) (vKEV) 🔥 [ CVE-2021-3152 ] Home Assistant HACS - Local File Inclusion ( @dhiyaneshdk ) [high] 🔥 What's Changed Bug Fixes CI: migrated nuclei GitHub action to native Node.js runtime (PR #16061 , PR #16049 ). Removed duplicate template for BeyondTrust (PR #16024 ). Removed duplicate matcher line in roundcube-log-disclosure.yaml (PR #16042 ). Corrected invalid cve-id classification field values across templates (PR #16023 ). Fixed invalid CPE format strings across templates (PR #15991 , PR #15828 ). Fixed tag formatting in CVE-2024-57727 , CVE-2023-38875 , CVE-2023-24322 (PR #15989 , PR #15897 , PR #15899 ). Corrected YAML formatting in Retool postMessage XSS template (PR #15952 ). Fixed file path for CVE-2026-2262 (PR #15998 ). Renamed joomla-htaccess.yaml → joomla-htaccess-file.yaml for clarity (PR #15987 ). Renamed contrastapi-domain-recon.yaml to correct directory (PR #16025 ). Renamed and updated superset-default-login.yaml (PR #15822 ). Release preparation for Nuclei Templates v10.4.2 (PR #15920 ). False Negatives Fixed FN in tomcat-default-login by ordering payloads to avoid LockOutRealm shunning (PR #16053 , Issue #15382 ). False Positives Reduced false positives and improved accuracy in the following templates: ingress-nginx-valid-admission.yaml — added 200-status guard for verbose-debug PHP frameworks (PR #16046 , Issue #14248 ). CVE-2024-2473 — verify hidden login URL disclosure to avoid FP on WPS Hide Login (PR #15985 , Issue #15871 ). CVE-2019-5544 — fix FP triggered when port 427 is closed (PR #15979 , Issue #15098 ). CVE-2023-45648 — bound Tomcat version regex (PR #15459 , Issue #15566 ). ldap-anonymous-login-detect.yaml — honor Port parameter instead of forcing 389 (PR #15430 , Issue #14736 ). sentry-panel — added title check to prevent FP (PR #15984 ). Enhancements Added Microsoft domain to mx-service-detector (PR #16030 ). Added registrar extractors to rdap-whois template (PR #15908 ). Added references to CVE-2020-15718 (PR #16058 ). Updated mitel-version-detect.yaml (PR #15839 ). Linked CVE-2021-31589 to existing beyond-trust-xss.yaml (Issue #15273 ). Templates Added [ CVE-2026-42167 ] ProFTPD mod_sql - Preauth User Backdoor ( @pussycat0x ) [high] 🔥 [ CVE-2026-42031 ] CKAN DataStore SQL Search - SQL Injection ( @theamanrawat ) [high] [ CVE-2026-41940 ] cPanel & WHM - Auth Bypass via Session-File CRLF Injection ( @wat

CVE-2017-6478CVE-2019-5544CVE-2020-15718CVE-2021-26947CVE-2021-3152CVE-2021-31589CVE-2021-45328CVE-2023-24322CVE-2023-38875CVE-2023-45648CVE-2023-49438CVE-2024-2473CVE-2024-26291CVE-2024-32825CVE-2024-38773CVE-2024-57727CVE-2025-10162CVE-2025-10897CVE-2025-11693CVE-2025-13390CVE-2025-1361CVE-2025-13801CVE-2025-23211CVE-2025-32395CVE-2025-41242CVE-2025-4524CVE-2025-49002CVE-2025-58226CVE-2025-59136CVE-2025-59341CVE-2025-59342CVE-2025-59582CVE-2025-62039CVE-2025-69411CVE-2025-9209CVE-2026-0560CVE-2026-1314CVE-2026-1368CVE-2026-21484CVE-2026-2262CVE-2026-23482CVE-2026-23483CVE-2026-23486CVE-2026-24423CVE-2026-27174CVE-2026-27176CVE-2026-28409CVE-2026-33017CVE-2026-33032CVE-2026-33057CVE-2026-33439CVE-2026-33626CVE-2026-35029CVE-2026-3844CVE-2026-39339CVE-2026-39363CVE-2026-39808CVE-2026-40105CVE-2026-40242CVE-2026-40308CVE-2026-40466CVE-2026-40887CVE-2026-41176CVE-2026-41179CVE-2026-41640CVE-2026-41641CVE-2026-41940CVE-2026-42031CVE-2026-42167CVE-2026-4631
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score10.1vtp-threat-v1-public
Public exploitation0 / 30
EPSS prediction10.05 / 20
Exploit availability0 / 15
Source independence0 / 15
Intelligence recency0 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
8.2 · HIGH
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-290
CPE records
1
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.