CVE-2026-35218
- EPSS 0.03%
- Veröffentlicht 03.04.2026 15:47:45
- Zuletzt bearbeitet 08.04.2026 21:18:49
Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity names (tables, views, queries, automations) using Svelte's {@html} directive without any sanitization. An authenticated user with...
- EPSS 0.55%
- Veröffentlicht 03.04.2026 15:45:40
- Zuletzt bearbeitet 08.04.2026 21:19:00
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. N...
CVE-2026-35214
- EPSS 0.15%
- Veröffentlicht 03.04.2026 15:43:12
- Zuletzt bearbeitet 08.04.2026 21:19:13
Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supplied filename directly to createTempFolder() without sanitizing path traversal sequences. An attacker...
CVE-2026-31818
- EPSS 0.01%
- Veröffentlicht 03.04.2026 15:41:13
- Zuletzt bearbeitet 08.04.2026 21:19:30
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered completely i...
CVE-2026-25044
- EPSS 0.07%
- Veröffentlicht 03.04.2026 15:38:23
- Zuletzt bearbeitet 08.04.2026 21:19:41
Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper sanitization or validation. User input is processed through processStringSync which allows t...
CVE-2026-25043
- EPSS 0.05%
- Veröffentlicht 03.04.2026 15:35:10
- Zuletzt bearbeitet 07.04.2026 13:20:55
Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functionality due to the absence of rate limiting, CAPTCHA, or abuse prevention mechanisms on the “Forgot Passw...
CVE-2026-33226
- EPSS 0.01%
- Veröffentlicht 20.03.2026 23:04:24
- Zuletzt bearbeitet 23.03.2026 19:14:07
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the REST datasource query preview endpoint (POST /api/queries/preview) makes server-side HTTP requests to any URL supplied by...
CVE-2026-31816
- EPSS 9.09%
- Veröffentlicht 09.03.2026 21:16:20
- Zuletzt bearbeitet 13.03.2026 17:33:41
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webh...
CVE-2026-30240
- EPSS 0.04%
- Veröffentlicht 09.03.2026 21:16:18
- Zuletzt bearbeitet 13.03.2026 17:46:41
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal vulnerability in the PWA (Progressive Web App) ZIP processing endpoint (POST /api/pwa/process-zip) allows an authenticat...
CVE-2026-25045
- EPSS 0.04%
- Veröffentlicht 09.03.2026 20:11:59
- Zuletzt bearbeitet 13.03.2026 19:21:13
Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of Vertical Privilege Escalation and IDOR (Insecure Direct Object Reference) due to missing server-side RBAC checks in the /api/glob...