ydata-profiling
Generate profile report for pandas DataFrame
Activity
- Latest release
- 4mo ago
- Total releases
- 35
- Cadence
- ~28 days
- Last 12 months
- 3
Details
- License
- MIT
- First release
- Jan 30, 2023
| Version | Released | |
|---|---|---|
4.18.4
patch
| ||
4.18.1
patch
| ||
4.18.0
minor
| ||
4.17.0
minor
| ||
4.16.1
patch
| ||
4.16.0
minor
| ||
4.15.1
patch
| ||
4.15.0
minor
| ||
4.14.0
minor
| ||
4.13.0
minor
| ||
4.12.2
patch
| ||
4.12.1
patch
| ||
4.12.0
minor
| ||
4.11.0
minor
| ||
4.10.0
minor
| ||
4.9.0
minor
| ||
4.8.3
minor
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.7.0
minor
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.6.5
patch
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.6.4
patch
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.6.3
patch
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.6.2
patch
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.6.1
patch
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.6.0
minor
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.5.1
patch
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.5.0
minor
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.4.0
minor
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.3.2
patch
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.3.1
patch
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.3.0
minor
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.2.0
minor
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.1.2
patch
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.1.1
patch
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.1.0
minor
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev | ||
4.0.0
initial
3 CVEs
CVE-2024-37062
PYSEC-2026-2062
GHSA-fpvj-m2h6-6wc5
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37063
PYSEC-2026-2060
GHSA-2r57-2mrh-ggjv
Jul 07, 2026
ydata cross-site scripting
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-37064
PYSEC-2026-2061
GHSA-cg49-hrj4-3rpr
Jul 07, 2026
ydata unsafe deserialization
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded. Affected versions
4.0.0
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.5.1
4.6.0
+ 7 more Show less
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.7.0
4.8.3
References Updated Jul 07, 2026 · Source: OSV.dev |