Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tooljet HIGH 7.5
CVE-2022-27978

Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.

No fix yet
Fix from $1,950 2023-04-26
Tooljet MEDIUM 5.4
CVE-2022-27979

A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

No fix yet
Fix from $1,600 2023-04-26
Tooljet MEDIUM 6.5
CVE-2022-4111

Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures over 2MB.

Fix: 1.27.0+
Fix from $1,600 2022-11-22
Tooljet HIGH 7.5
CVE-2022-3422

Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the fo…

Fix: 1.26.1+
Fix from $1,950 2022-10-07
Tooljet HIGH 8.8
CVE-2022-3019

The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comme…

Fix: 1.23.0+
Fix from $1,950 2022-08-29
Tooljet HIGH 8.8
CVE-2022-2631

Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.

Fix: 1.19.0+
Fix from $1,950 2022-08-02
Tooljet HIGH 8.0
CVE-2022-2037

Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.

Fix: 1.16.0+
Fix from $1,950 2022-06-09
Tooljet HIGH 8.8
CVE-2022-23067

ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite li…

Fix: after 1.2.2
Fix from $1,950 2022-05-18
Tooljet MEDIUM 5.4
CVE-2022-23068

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name f…

Fix: after 1.10.2
Fix from $1,600 2022-05-18