Microsoft Power Bi Report Server — known CVE vulnerabilities
Every CVE whose affected-product data names Microsoft Power Bi Report Server, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (11)
CVE-2026-65811 — CVSS 8.8 (high): Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2026-21229 — CVSS 8.0 (high): Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2026-58647 — CVSS 8.0 (high): Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform…
CVE-2021-41372 — CVSS 7.6 (high): A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix)…
CVE-2020-1173 — CVSS 6.8 (medium): A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An…
CVE-2019-1332 — CVSS 6.1 (medium): A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a…