Python

flask-appbuilder

Latest secure version 5.2.2

Simple and rapid application development framework, built on top of Flask. includes detailed security, auto CRUD generation for your models, google charts and much more.

All Versions

Vulnerabilities (Public)

Known vulnerabilities and security issues detected in the extension's dependencies and code.

Vulnerability IDAdvisoryAffected Versions
CVE-2024-25128** DISPUTED ** Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that…
Critical
<4.3.11
CVE-2023-29483Flask-appbuilder's update from dnspython 2.4.2 to 2.6.1 addresses CVE-2023-29483.
High
<4.5.1
CVE-2023-29005Flask-AppBuilder 4.3.0 includes a fix for CVE-2023-29005: Versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to en…
High
<4.3.0
CVE-2025-58065Affected versions of the flask-appbuilder package are vulnerable to Improper Authentication due to the password-reset endpoint remaining registered and reachable when non-AUTH_DB authentication (e.g.,…
Medium
<4.8.1
CVE-2025-32962Affected versions of the `Flask-AppBuilder` package are vulnerable to Open Redirect due to improper validation of the Host header in HTTP requests. The `redirect` function fails to verify that the Hos…
Medium
<4.6.2
CVE-2025-24023User enumeration in database authentication in Flask-AppBuilder <= 4.5.3 and werkzeug >= 3.0.0. Allows for a non-authenticated user to enumerate existing usernames by timing the response time from the…
Medium
<4.5.3
CVE-2024-45314In flask-appbuilder affected versions, the authentication database login form's default cache directives allow browsers to locally store sensitive data. This poses a security risk, particularly in env…
Medium
<4.5.1
CVE-2024-27083Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user …
Medium
>=4.1.4,<4.2.1
CVE-2023-34110Flask-AppBuilder 4.3.2 includes a fix for an Information Disclosure vulnerability. https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-jhpr-j7cq-3jp3
Low
<4.3.2
CVE-2022-31177Flask-AppBuilder 4.1.3 includes a fix for CVE-2022-31177: Possible to infer sensitive information through query strings. https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-32ff-4g7…
Low
<4.1.3
Page 1

Safety Discovered Vulnerabilities

Additional security issues found by Safety, exclusive to our platform.

Safety discovered vulnerability data is available for Enterprise customers

Book a call with us to see Safety in action.

Vulnerable Functions

Functions linked to known vulnerabilities in this package.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.