Vulnerabilities in budibase
81 resultsVexday analysis
Budibase apresenta footprint de risco mínimo com apenas 1 CVE registrado na base, sem incidentes sob ataque ativo ou vulnerabilidades críticas. A fraqueza identificada (CWE-913 - Improper Control of Dynamically-Managed Code Execution) é de severidade moderada e não há registros recentes de novas exposições, indicando perfil de risco baixo no curto prazo.
CVE-2026-31816CRITICALBudibase Universal Auth Bypass via Webhook Query Param InjectionEPSS 2.2%CVE-2026-35216CRITICALBudibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation StepEPSS 1.2%CVE-2022-3225HIGHImproper Control of Dynamically-Managed Code Resources in budibase/budibaseEPSS 0.9%CVE-2026-82244CRITICALBudibase before 3.41.3 Remote Code Execution via Plugin eval()EPSS 0.9%CVE-2026-35214HIGHBudibase: Path traversal in plugin file upload enables arbitrary directory deletion and file writeEPSS 0.7%CVE-2023-29010MEDIUMBudiBase Server-Side Request Forgery vulnerabilityEPSS 0.6%CVE-2026-41428CRITICALBudibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected EndpointsEPSS 0.6%CVE-2026-72850CRITICALBudibase before 3.40.0 Arbitrary File Write via Path TraversalEPSS 0.6%CVE-2026-73300CRITICALBudibase: SQL Injection via `multipleStatements: true`EPSS 0.6%CVE-2026-27702CRITICALBudibase Vulnerable to Remote Code Execution via Unsafe eval() in View Filter Map Function (Budibase Cloud)EPSS 0.6%CVE-2026-25040MEDIUMBudibase Vulnerable to Privilege Escalation via API Abuse – Creator Can Invite Users with Admin/Any RoleEPSS 0.5%CVE-2026-73407CRITICALBudibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152))EPSS 0.5%CVE-2026-54350CRITICALBudibase: Anonymous NoSQL operator injection via published-app query templatesEPSS 0.5%CVE-2026-73305HIGHBudibase: Privilege escalation via public role assignment API missing app-level authorizationEPSS 0.5%CVE-2026-73406HIGHBudibase: Unauthenticated user information disclosure via public tenant user lookup endpointEPSS 0.5%CVE-2026-73618HIGHBudibase Server before 3.40.0 NoSQL Injection via JSON ParameterEPSS 0.5%CVE-2026-54352CRITICALBudibase: Arbitrary file read by workspace-builder via PWA-zip symlink uploadEPSS 0.5%CVE-2026-73304MEDIUMBudibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role UsersEPSS 0.5%CVE-2026-48128MEDIUMBudibase: SSRF via User-Controlled queryId in Automation Execute Query StepEPSS 0.5%CVE-2026-25041HIGHBudibase has a Command Injection in PostgreSQL Dump CommandEPSS 0.5%