CVE-2026-19754
- EPSS 0.29%
- Veröffentlicht 02.09.2026 03:29:38
- Zuletzt bearbeitet 02.09.2026 19:23:13
Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treated as a SQL template and interp...
CVE-2026-81335
- EPSS 0.42%
- Veröffentlicht 27.08.2026 14:50:42
- Zuletzt bearbeitet 23.09.2026 17:17:43
Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch and record-name views in backend/src/baserow/contrib/builder/api/data_sources/views.py are declared with a permission class that ...
CVE-2026-76837
- EPSS 0.2%
- Veröffentlicht 24.08.2026 17:36:02
- Zuletzt bearbeitet 23.09.2026 17:17:45
Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/account/ stores the first_name value verbatim, and the mention renderer in web-frontend/modules/core/editor/mention.js builds its elem...
CVE-2026-18817
- EPSS 0.2%
- Veröffentlicht 04.08.2026 22:00:12
- Zuletzt bearbeitet 12.08.2026 20:59:00
A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. ...
- EPSS 0.34%
- Veröffentlicht 04.08.2026 21:45:08
- Zuletzt bearbeitet 12.08.2026 20:59:00
A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to improper authen...
CVE-2021-22255
- EPSS 1.29%
- Veröffentlicht 20.08.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:48
SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by inserting an internal address.