CVE-2026-73068
- EPSS 0.19%
- Veröffentlicht 11.08.2026 15:02:13
- Zuletzt bearbeitet 13.08.2026 15:20:05
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations agai...
CVE-2026-54344
- EPSS 0.17%
- Veröffentlicht 08.07.2026 15:08:19
- Zuletzt bearbeitet 09.07.2026 19:40:42
ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview deployment workflow interpolates github.event.comment.body directly into a bash conditional in a run step, allowing any GitHub user w...
CVE-2026-55411
- EPSS 0.13%
- Veröffentlicht 25.06.2026 16:08:14
- Zuletzt bearbeitet 25.06.2026 19:16:42
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint POST /api/data-sources/decrypt returns the decrypted plaintext for any ...
CVE-2026-55412
- EPSS 0.19%
- Veröffentlicht 25.06.2026 16:07:13
- Zuletzt bearbeitet 25.06.2026 19:16:42
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, there's an SSRF in the RestAPI data source component. The RestAPI data source executes HTTP request...
CVE-2026-55413
- EPSS 0.26%
- Veröffentlicht 25.06.2026 16:03:40
- Zuletzt bearbeitet 25.06.2026 19:16:42
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, any authenticated user with builder role (free tier) can overwrite a globally-shared marketplace pl...
CVE-2022-27978
- EPSS 1.04%
- Veröffentlicht 26.04.2023 16:15:09
- Zuletzt bearbeitet 09.07.2026 01:17:24
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.
CVE-2022-27979
- EPSS 0.48%
- Veröffentlicht 26.04.2023 16:15:09
- Zuletzt bearbeitet 09.07.2026 01:17:24
A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component.
CVE-2022-4111
- EPSS 0.75%
- Veröffentlicht 22.11.2022 03:15:14
- Zuletzt bearbeitet 21.11.2024 07:34:36
Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures over 2MB.
CVE-2022-3422
- EPSS 0.83%
- Veröffentlicht 07.10.2022 11:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:28
Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass
CVE-2022-3348
- EPSS 0.88%
- Veröffentlicht 28.09.2022 09:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:20
Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a little bit more specific, because it is needed to be an editor in the same app as the victim.