Simple and rapid application development framework, built on top of Flask. includes detailed security, auto CRUD generation for your models, google charts and much more.
BSD-3-Clause
All Versions
Vulnerabilities (Public)
Known vulnerabilities and security issues detected in the extension's dependencies and code.
| Vulnerability ID | Advisory | Affected Versions | |||
|---|---|---|---|---|---|
| CVE-2024-25128 | ** DISPUTED ** Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that… | Critical | – | – | <4.3.11 |
| CVE-2023-29483 | Flask-appbuilder's update from dnspython 2.4.2 to 2.6.1 addresses CVE-2023-29483. | High | – | – | <4.5.1 |
| CVE-2023-29005 | Flask-AppBuilder 4.3.0 includes a fix for CVE-2023-29005: Versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to en… | High | – | – | <4.3.0 |
| CVE-2025-58065 | Affected versions of the flask-appbuilder package are vulnerable to Improper Authentication due to the password-reset endpoint remaining registered and reachable when non-AUTH_DB authentication (e.g.,… | Medium | – | – | <4.8.1 |
| CVE-2025-32962 | Affected versions of the `Flask-AppBuilder` package are vulnerable to Open Redirect due to improper validation of the Host header in HTTP requests. The `redirect` function fails to verify that the Hos… | Medium | – | – | <4.6.2 |
| CVE-2025-24023 | User enumeration in database authentication in Flask-AppBuilder <= 4.5.3 and werkzeug >= 3.0.0. Allows for a non-authenticated user to enumerate existing usernames by timing the response time from the… | Medium | – | – | <4.5.3 |
| CVE-2024-45314 | In flask-appbuilder affected versions, the authentication database login form's default cache directives allow browsers to locally store sensitive data. This poses a security risk, particularly in env… | Medium | – | – | <4.5.1 |
| CVE-2024-27083 | Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user … | Medium | – | – | >=4.1.4,<4.2.1 |
| CVE-2023-34110 | Flask-AppBuilder 4.3.2 includes a fix for an Information Disclosure vulnerability. https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-jhpr-j7cq-3jp3 | Low | – | – | <4.3.2 |
| CVE-2022-31177 | Flask-AppBuilder 4.1.3 includes a fix for CVE-2022-31177: Possible to infer sensitive information through query strings. https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-32ff-4g7… | Low | – | – | <4.1.3 |
Page 1
Safety Discovered Vulnerabilities
Additional security issues found by Safety, exclusive to our platform.

