Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-54350 Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the… Budibase 3.39.12+ Fix from $2,3002026-06-26 CRITICAL 9.6 CVE-2026-54351 Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HT… Budibase 3.39.9+ Fix from $2,3002026-06-26 CRITICAL 9.6 CVE-2026-54352 Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a b… Budibase 3.39.9+ Fix from $2,3002026-06-26 HIGH 7.1 CVE-2026-54353 Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist t… Budibase 3.39.9+ Fix from $1,9502026-06-26 CRITICAL 9.4 CVE-2026-50137 Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-so… Budibase 3.39.0+ Fix from $2,3002026-06-26 HIGH 7.3 CVE-2026-50132 Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required)… Budibase 3.39.0+ Fix from $1,9502026-06-26 MEDIUM 5.3 CVE-2026-50136 Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject… Budibase 3.39.3+ Fix from $1,6002026-06-26 HIGH 8.1 CVE-2026-42239 Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnl… Budibase 3.35.10+ Fix from $1,9502026-05-07 CRITICAL 9.1 CVE-2026-41428 Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-a… Budibase 3.35.4+ Fix from $2,3002026-04-24 CRITICAL 9.0 CVE-2026-35216EPSS 12% Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Bud… Budibase 3.33.4+ Fix from $2,3002026-04-03 HIGH 8.7 CVE-2026-35214 Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supp… Budibase 3.33.4+ Fix from $1,9502026-04-03 HIGH 8.7 CVE-2026-35218 Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity names (tables, views, querie… Budibase 3.32.5+ Fix from $1,9502026-04-03 CRITICAL 9.9 CVE-2026-31818 Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST d… Budibase 3.33.4+ Fix from $2,3002026-04-03 HIGH 8.8 CVE-2026-25044 Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync withou… Budibase 3.33.4+ Fix from $1,9502026-04-03 HIGH 7.5 CVE-2026-25043 Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functional… Budibase 3.23.25+ Fix from $1,9502026-04-03 HIGH 8.7 CVE-2026-33226 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the REST datasource quer… Budibase after 3.30.6 Fix from $1,9502026-03-20 CRITICAL 9.1 CVE-2026-31816EPSS 15% Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() m… Budibase after 3.31.4 Fix from $2,3002026-03-09 HIGH 8.1 CVE-2026-30240 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal vulnerability in th… Budibase after 3.31.5 Fix from $1,9502026-03-09 CRITICAL 9.0 CVE-2026-25737 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerabili… Budibase after 3.24.0 Fix from $2,3002026-03-09 HIGH 8.8 CVE-2026-25045 Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of Vertical Privilege Escalatio… Budibase after 3.32.3 Fix from $1,9502026-03-09 HIGH 7.2 CVE-2026-25041 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the PostgreSQL integration construc… Budibase after 3.23.22 Fix from $1,9502026-03-09 CRITICAL 9.0 CVE-2026-27702 Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability i… Budibase 3.30.4+ Fix from $2,3002026-02-25 HIGH 8.8 CVE-2026-25040 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and including 3.26.3, a Creator-level use… Budibase after 3.26.3 Fix from $1,9502026-01-29 MEDIUM 6.5 CVE-2023-29010 Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023) are vulnerable to S… Budibase 2.4.3+ Fix from $1,6002023-04-06 MEDIUM 5.7 CVE-2022-3225 Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20. Budibase 1.3.20+ Fix from $1,6002022-09-16