CVE-2026-28360: low-severity vulnerability in nocodb
NocoDB: Plaintext Storage of Shared View Passwords
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 2.7epss 0.3%
exploitation probability
0.3%top 75% of all CVEs
observed exploitation
nono source reports it
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored in plaintext in the database and compared using direct string equality. This issue has been patched in version 0.301.3.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
Affected products
nocodb · nocodbRelated CVEs — nocodb
In the same product, most dangerous first.
CVE-2022-22120MEDIUMNocoDB - Observable Discrepancy in the password-reset featureEPSS 1.4%CVE-2022-22121HIGHNocoDB - CSV Injection in User ManagementEPSS 1.2%CVE-2023-43794MEDIUMSQL Injection in nocodbEPSS 0.8%CVE-2026-28358LOWNocoDB: User Enumeration via Password Reset EndpointEPSS 0.7%CVE-2025-27506MEDIUMNocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password PageEPSS 0.7%CVE-2023-50718MEDIUMNocoDB SQL Injection vulnerabilityEPSS 0.7%