Budibase

Budibase

38 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.28%
  • Veröffentlicht 07.05.2026 18:49:59
  • Zuletzt bearbeitet 04.06.2026 16:10:31

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie via documen...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 24.04.2026 19:17:29
  • Zuletzt bearbeitet 28.04.2026 15:39:13

Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoint patterns against ctx.request.url. Since ctx.request.url in Koa includes the query strin...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 03.04.2026 15:47:45
  • Zuletzt bearbeitet 08.04.2026 21:18:49

Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity names (tables, views, queries, automations) using Svelte's {@html} directive without any sanitization. An authenticated user with...

Exploit
  • EPSS 11.98%
  • Veröffentlicht 03.04.2026 15:45:40
  • Zuletzt bearbeitet 08.04.2026 21:19:00

Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. N...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 03.04.2026 15:43:12
  • Zuletzt bearbeitet 08.04.2026 21:19:13

Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supplied filename directly to createTempFolder() without sanitizing path traversal sequences. An attacker...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 03.04.2026 15:41:13
  • Zuletzt bearbeitet 08.04.2026 21:19:30

Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered completely i...

  • EPSS 0.47%
  • Veröffentlicht 03.04.2026 15:38:23
  • Zuletzt bearbeitet 08.04.2026 21:19:41

Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper sanitization or validation. User input is processed through processStringSync which allows t...

  • EPSS 0.3%
  • Veröffentlicht 03.04.2026 15:35:10
  • Zuletzt bearbeitet 21.04.2026 01:35:13

Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functionality due to the absence of rate limiting, CAPTCHA, or abuse prevention mechanisms on the “Forgot Passw...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 20.03.2026 23:04:24
  • Zuletzt bearbeitet 23.03.2026 19:14:07

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the REST datasource query preview endpoint (POST /api/queries/preview) makes server-side HTTP requests to any URL supplied by...

Exploit
  • EPSS 15.34%
  • Veröffentlicht 09.03.2026 21:16:20
  • Zuletzt bearbeitet 13.03.2026 17:33:41

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webh...