CVE-2026-42239
- EPSS 0.28%
- Veröffentlicht 07.05.2026 18:49:59
- Zuletzt bearbeitet 04.06.2026 16:10:31
Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie via documen...
CVE-2026-41428
- EPSS 0.45%
- Veröffentlicht 24.04.2026 19:17:29
- Zuletzt bearbeitet 28.04.2026 15:39:13
Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoint patterns against ctx.request.url. Since ctx.request.url in Koa includes the query strin...
CVE-2026-35218
- EPSS 0.33%
- Veröffentlicht 03.04.2026 15:47:45
- Zuletzt bearbeitet 08.04.2026 21:18:49
Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity names (tables, views, queries, automations) using Svelte's {@html} directive without any sanitization. An authenticated user with...
- EPSS 11.98%
- Veröffentlicht 03.04.2026 15:45:40
- Zuletzt bearbeitet 08.04.2026 21:19:00
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. N...
CVE-2026-35214
- EPSS 0.55%
- Veröffentlicht 03.04.2026 15:43:12
- Zuletzt bearbeitet 08.04.2026 21:19:13
Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) passes the user-supplied filename directly to createTempFolder() without sanitizing path traversal sequences. An attacker...
CVE-2026-31818
- EPSS 0.38%
- Veröffentlicht 03.04.2026 15:41:13
- Zuletzt bearbeitet 08.04.2026 21:19:30
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered completely i...
CVE-2026-25044
- EPSS 0.47%
- Veröffentlicht 03.04.2026 15:38:23
- Zuletzt bearbeitet 08.04.2026 21:19:41
Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper sanitization or validation. User input is processed through processStringSync which allows t...
CVE-2026-25043
- EPSS 0.3%
- Veröffentlicht 03.04.2026 15:35:10
- Zuletzt bearbeitet 21.04.2026 01:35:13
Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functionality due to the absence of rate limiting, CAPTCHA, or abuse prevention mechanisms on the “Forgot Passw...
CVE-2026-33226
- EPSS 0.37%
- Veröffentlicht 20.03.2026 23:04:24
- Zuletzt bearbeitet 23.03.2026 19:14:07
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the REST datasource query preview endpoint (POST /api/queries/preview) makes server-side HTTP requests to any URL supplied by...
CVE-2026-31816
- EPSS 15.34%
- Veröffentlicht 09.03.2026 21:16:20
- Zuletzt bearbeitet 13.03.2026 17:33:41
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webh...