budibase
Cloud & SaaScommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting budibase.
- CVE-2026-54356Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`7.1
- CVE-2026-73410Budibase: SSRF via DNS rebinding in the REST datasource integration8.5
- CVE-2026-64657Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL8.4
- CVE-2026-72859Budibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URL7.7
- CVE-2026-73305Budibase: Privilege escalation via public role assignment API missing app-level authorization8.8
- CVE-2026-73304Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users4.9
- CVE-2026-73408Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector7.6
- CVE-2026-72857Budibase before 3.40.0 Credential Exposure via STRING Fields7.7
- CVE-2026-72856Budibase before 3.40.0 Authentication Bypass via Tenant Owner Email8.1
- CVE-2026-72855Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST8.5
- CVE-2026-72853Budibase before 3.40.0 SQL Injection via Oracle connector7.6
- CVE-2026-72851Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook10.0
- CVE-2026-72850Budibase before 3.40.0 Arbitrary File Write via Path Traversal9.1
- CVE-2026-72849Budibase before 3.40.0 Identity Confusion via Chat-Link Handoff CSRF7.7
- CVE-2026-73617Budibase before 3.40.0 NoSQL Injection via MongoDB datasource7.1