Nocobase

Nocobase

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 21.09.2026 00:00:00
  • Zuletzt bearbeitet 22.09.2026 20:00:03

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

  • EPSS 0.32%
  • Veröffentlicht 21.09.2026 00:00:00
  • Zuletzt bearbeitet 22.09.2026 20:00:03

A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.

  • EPSS 0.17%
  • Veröffentlicht 02.09.2026 00:37:55
  • Zuletzt bearbeitet 16.09.2026 13:42:44

NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup through the collection API that executes in the browsers ...

  • EPSS 0.37%
  • Veröffentlicht 15.07.2026 20:19:54
  • Zuletzt bearbeitet 18.07.2026 02:17:10

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the database.schema value from _metadata....

  • EPSS 0.59%
  • Veröffentlicht 15.07.2026 20:16:43
  • Zuletzt bearbeitet 20.07.2026 16:17:05

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgR...

  • EPSS 0.27%
  • Veröffentlicht 15.07.2026 20:13:52
  • Zuletzt bearbeitet 16.07.2026 16:19:12

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collect...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 07.07.2026 19:27:58
  • Zuletzt bearbeitet 14.07.2026 23:17:31

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request nodes, custom...

Exploit
  • EPSS 1.88%
  • Veröffentlicht 07.05.2026 04:16:28
  • Zuletzt bearbeitet 12.05.2026 16:51:23

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryParentSQL() function in the core database package constructs a recursive CTE query by joining nodeIds w...

Exploit
  • EPSS 1.83%
  • Veröffentlicht 07.05.2026 04:13:33
  • Zuletzt bearbeitet 07.05.2026 20:23:22

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the checkSQL() validation function that blocks dangerous SQL keywords (e.g., pg_read_file, LOAD_FILE, dblink) is...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 18.04.2026 00:16:38
  • Zuletzt bearbeitet 13.05.2026 20:53:48

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-...