CVEs we hold for Budibase
Records whose assigning authority named Budibase as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-82242Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorizationbudibase server
CVE-2026-73409Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFilebudibase
CVE-2026-73408Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connectorbudibase
CVE-2026-73407Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152))budibase
CVE-2026-73406Budibase: Unauthenticated user information disclosure via public tenant user lookup endpointbudibase
CVE-2026-73308Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Buildersbudibase
CVE-2026-73305Budibase: Privilege escalation via public role assignment API missing app-level authorizationbudibase
CVE-2026-73304Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Usersbudibase
CVE-2026-73303Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against…budibase
CVE-2026-73302Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verifiedbudibase
CVE-2026-73301Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappingsbudibase
CVE-2026-72859Budibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URLbudibase server
CVE-2026-54356Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`budibase
CVE-2026-54351Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Overridebudibase
CVE-2026-54350Budibase: Anonymous NoSQL operator injection via published-app query templatesbudibase
CVE-2026-50137Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed…budibase
CVE-2026-50136Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentialsbudibase
CVE-2026-50132Budibase: Chat Identity Link Hijacking via Missing Consent & CSRF — Account Impersonation in Budibasebudibase
CVE-2026-48153Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadatabudibase
CVE-2026-48152Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URLbudibase
CVE-2026-48151Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schemabudibase
CVE-2026-48150Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assignbudibase
CVE-2026-48149Budibase: Stored XSS in Text component: BASIC users execute JS in admin session via MarkdownViewer innerHTML +…budibase
CVE-2026-48147Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Workerbudibase
CVE-2026-48146Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protectionbudibase
CVE-2026-46427Budibase: Snowflake private key returned unmasked from datasource API to BASIC usersbudibase
CVE-2026-46425Budibase: SCIM endpoints lack role-based authorization, BASIC users CRUD tenant usersbudibase
CVE-2026-46424Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up…budibase
CVE-2026-45719Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views APIbudibase
CVE-2026-45718Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope Rowsbudibase
CVE-2026-45717Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access…budibase
CVE-2026-45716Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configurationbudibase
CVE-2026-45548Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validationbudibase
CVE-2026-45061Budibase: SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)budibase
CVE-2026-42239Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeoverbudibase
CVE-2026-41428Budibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected…budibase
CVE-2026-35219Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklistbudibase
CVE-2026-35218Budibase: Stored XSS via unsanitized entity names rendered with {@html} in Builder Command Palettebudibase
CVE-2026-35216Budibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Stepbudibase
CVE-2026-35214Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file writebudibase
CVE-2026-33226Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Previewbudibase
CVE-2026-31818Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklistbudibase
CVE-2026-30240Budibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All Environment Secretsbudibase
CVE-2026-27702Budibase Vulnerable to Remote Code Execution via Unsafe eval() in View Filter Map Function (Budibase Cloud)budibase
CVE-2026-25737Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS)budibase
CVE-2026-25045Budibase Critical Privilege Escalation & IDOR via Missing RBAC on User Role Management (Creator-Role)budibase
CVE-2026-25043Budibase: Unauthenticated Password Reset Endpoint Lacks Rate Limiting, Enabling Email Floodingbudibase
CVE-2026-25040Budibase Vulnerable to Privilege Escalation via API Abuse – Creator Can Invite Users with Admin/Any Rolebudibase
CVE-2022-3225Improper Control of Dynamically-Managed Code Resources in budibase/budibasebudibase/budibase
81 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.