Budibase

Budibase

66 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 13.08.2026 21:54:43
  • Zuletzt bearbeitet 18.08.2026 02:17:28

Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can i...

  • EPSS 0.19%
  • Veröffentlicht 12.08.2026 19:19:59
  • Zuletzt bearbeitet 14.08.2026 22:17:11

Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. A builder could submit absolute...

  • EPSS 0.42%
  • Veröffentlicht 12.08.2026 19:09:55
  • Zuletzt bearbeitet 12.08.2026 20:17:55

Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials from getAuthHeaders and defaultHeaders without requiring the final request destination to match the d...

  • EPSS 0.37%
  • Veröffentlicht 12.08.2026 19:03:51
  • Zuletzt bearbeitet 13.08.2026 15:20:13

Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller...

  • EPSS 0.29%
  • Veröffentlicht 12.08.2026 19:01:15
  • Zuletzt bearbeitet 14.08.2026 22:17:10

Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.outputs.user.oauth2, broadcast BuilderSocketEvent.AutomationTestProgress to the app ...

  • EPSS 0.31%
  • Veröffentlicht 12.08.2026 18:59:52
  • Zuletzt bearbeitet 12.08.2026 20:17:54

Budibase is an open-source low-code platform. Prior to 3.39.4, uploadUrl in packages/server/src/utilities/fileUtils.ts used a bare server-side fetch for string attachment values passed by processAttachments in packages/server/src/sdk/workspace/ai/hel...

  • EPSS 0.32%
  • Veröffentlicht 12.08.2026 18:56:08
  • Zuletzt bearbeitet 13.08.2026 13:19:17

Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers/global/auth.ts only for existing users, while packages/worker/src/middleware/...

  • EPSS 0.23%
  • Veröffentlicht 12.08.2026 18:51:38
  • Zuletzt bearbeitet 12.08.2026 23:17:24

Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated attac...

  • EPSS 0.25%
  • Veröffentlicht 12.08.2026 18:08:07
  • Zuletzt bearbeitet 14.08.2026 22:17:10

Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate tenant groups, ...

  • EPSS 0.38%
  • Veröffentlicht 12.08.2026 18:05:51
  • Zuletzt bearbeitet 12.08.2026 20:17:54

Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQ...