CVE-2026-28359: medium-severity vulnerability in nocodb
NocoDB: Stored Cross-Site Scripting via Rich Text Field
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.3%
exploitation probability
0.3%top 84% of all CVEs
observed exploitation
nono source reports it
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Editor role can inject arbitrary HTML into Rich Text cells by bypassing the TipTap editor and sending raw HTML via the API. This issue has been patched in version 0.301.3.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
nocodb · nocodbRelated CVEs — nocodb
In the same product, most dangerous first.
CVE-2022-22120MEDIUMNocoDB - Observable Discrepancy in the password-reset featureEPSS 1.4%CVE-2022-22121HIGHNocoDB - CSV Injection in User ManagementEPSS 1.2%CVE-2023-43794MEDIUMSQL Injection in nocodbEPSS 0.8%CVE-2026-28358LOWNocoDB: User Enumeration via Password Reset EndpointEPSS 0.7%CVE-2025-27506MEDIUMNocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password PageEPSS 0.7%CVE-2023-50718MEDIUMNocoDB SQL Injection vulnerabilityEPSS 0.7%