Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Budibase CRITICAL 9.8
CVE-2026-54350

Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the…

Fix: 3.39.12+
Fix from $2,300 2026-06-26
Budibase CRITICAL 9.6
CVE-2026-54351

Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HT…

Fix: 3.39.9+
Fix from $2,300 2026-06-26
Budibase CRITICAL 9.6
CVE-2026-54352

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a b…

Fix: 3.39.9+
Fix from $2,300 2026-06-26
Budibase HIGH 7.1
CVE-2026-54353

Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist t…

Fix: 3.39.9+
Fix from $1,950 2026-06-26
Budibase CRITICAL 9.4
CVE-2026-50137

Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-so…

Fix: 3.39.0+
Fix from $2,300 2026-06-26
Budibase HIGH 7.3
CVE-2026-50132

Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required)…

Fix: 3.39.0+
Fix from $1,950 2026-06-26
Budibase MEDIUM 5.3
CVE-2026-50136

Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject…

Fix: 3.39.3+
Fix from $1,600 2026-06-26
Budibase HIGH 8.1
CVE-2026-42239

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnl…

Fix: 3.35.10+
Fix from $1,950 2026-05-07
Budibase CRITICAL 9.1
CVE-2026-41428

Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-a…

Fix: 3.35.4+
Fix from $2,300 2026-04-24
Budibase CRITICAL 9.0
CVE-2026-35216EPSS 12%

Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Bud…

Fix: 3.33.4+
Fix from $2,300 2026-04-03
Budibase HIGH 8.7
CVE-2026-35214

Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supp…

Fix: 3.33.4+
Fix from $1,950 2026-04-03
Budibase HIGH 8.7
CVE-2026-35218

Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity names (tables, views, querie…

Fix: 3.32.5+
Fix from $1,950 2026-04-03
Budibase CRITICAL 9.9
CVE-2026-31818

Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST d…

Fix: 3.33.4+
Fix from $2,300 2026-04-03
Budibase HIGH 8.8
CVE-2026-25044

Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync withou…

Fix: 3.33.4+
Fix from $1,950 2026-04-03
Budibase HIGH 7.5
CVE-2026-25043

Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functional…

Fix: 3.23.25+
Fix from $1,950 2026-04-03
Budibase HIGH 8.7
CVE-2026-33226

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the REST datasource quer…

Fix: after 3.30.6
Fix from $1,950 2026-03-20
Budibase CRITICAL 9.1
CVE-2026-31816EPSS 15%

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() m…

Fix: after 3.31.4
Fix from $2,300 2026-03-09
Budibase HIGH 8.1
CVE-2026-30240

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal vulnerability in th…

Fix: after 3.31.5
Fix from $1,950 2026-03-09
Budibase CRITICAL 9.0
CVE-2026-25737

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerabili…

Fix: after 3.24.0
Fix from $2,300 2026-03-09
Budibase HIGH 8.8
CVE-2026-25045

Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of Vertical Privilege Escalatio…

Fix: after 3.32.3
Fix from $1,950 2026-03-09
Budibase HIGH 7.2
CVE-2026-25041

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the PostgreSQL integration construc…

Fix: after 3.23.22
Fix from $1,950 2026-03-09
Budibase CRITICAL 9.0
CVE-2026-27702

Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability i…

Fix: 3.30.4+
Fix from $2,300 2026-02-25
Budibase HIGH 8.8
CVE-2026-25040

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and including 3.26.3, a Creator-level use…

Fix: after 3.26.3
Fix from $1,950 2026-01-29
Budibase MEDIUM 6.5
CVE-2023-29010

Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023) are vulnerable to S…

Fix: 2.4.3+
Fix from $1,600 2023-04-06
Budibase MEDIUM 5.7
CVE-2022-3225

Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20.

Fix: 1.3.20+
Fix from $1,600 2022-09-16