Nocodb

Nocodb

59 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 23.06.2026 21:17:00
  • Zuletzt bearbeitet 25.06.2026 14:21:00

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the connection-test endpoint opened a raw TCP socket to the user-supplied database host without resolving and range-checking the destination, so private and link-local add...

  • EPSS 0.2%
  • Veröffentlicht 23.06.2026 21:16:59
  • Zuletzt bearbeitet 25.06.2026 14:21:00

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, sign-in response timing differed between known and unknown email addresses because the unknown-user branch returned without performing a password hash comparison. This vul...

  • EPSS 0.24%
  • Veröffentlicht 23.06.2026 21:16:59
  • Zuletzt bearbeitet 25.06.2026 14:21:00

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, Public shared-view endpoints exposed values from columns that the view owner had hidden, via three independent paths: groupBy returned raw values for any column named in t...

  • EPSS 0.24%
  • Veröffentlicht 23.06.2026 21:16:59
  • Zuletzt bearbeitet 25.06.2026 14:21:00

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin called window.location.replace() on a path extracted from the URL hash fragment after only checking hashPath.startsWith('/'). Protocol-...

  • EPSS 0.26%
  • Veröffentlicht 23.06.2026 21:16:59
  • Zuletzt bearbeitet 25.06.2026 14:21:00

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the password-reset page rendered the URL token directly into a JavaScript string literal in a server-rendered EJS template. EJS <%= %> HTML-entity-encodes a fixed set of c...

  • EPSS 0.22%
  • Veröffentlicht 23.06.2026 21:16:59
  • Zuletzt bearbeitet 25.06.2026 14:21:00

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, an authenticated user with columnAdd permission on a Postgres-backed base can inject arbitrary SQL into the formula engine via the optional direction argument of ARRAYSORT...

  • EPSS 0.24%
  • Veröffentlicht 23.06.2026 21:16:58
  • Zuletzt bearbeitet 25.06.2026 14:21:00

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without verifying that the column was visible in the shared view, so anyone holding a share ...

  • EPSS 0.2%
  • Veröffentlicht 23.06.2026 21:16:58
  • Zuletzt bearbeitet 25.06.2026 14:21:00

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authenticate requests until their cache entry expired, because the auth cache was not invalidated by token value at deletion time. The API ...

  • EPSS 0.24%
  • Veröffentlicht 23.06.2026 21:16:58
  • Zuletzt bearbeitet 25.06.2026 14:21:00

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the upload-by-URL path did not enforce NC_ATTACHMENT_FIELD_SIZE against either the remote file's advertised Content-Length or the decoded length of a data: URI, allowing a...

  • EPSS 0.3%
  • Veröffentlicht 23.06.2026 21:16:58
  • Zuletzt bearbeitet 25.06.2026 14:21:00

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, shared-base sessions were granted the same base-member capabilities as authenticated viewers. Using only the shared-base UUID (xc-shared-base-id), an attacker could enumer...