Vulnerabilidades en ToolJet
12 resultadosAnálisis Vexday
ToolJet apresenta 6 vulnerabilidades registradas, com 4 divulgadas nos últimos 90 dias, indicando atividade recente de descoberta. A fraqueza dominante é exposição de informações (CWE-200), com 1 vulnerabilidade crítica; nenhuma está sob exploração ativa conhecida (KEV), reduzindo a urgência imediata, mas a renovação acelerada de achados merece monitoramento contínuo.
CVE-2022-23067HIGHToolJet - Token Leakage via Referer HeaderEPSS 1.3%CVE-2022-2631CRITICALImproper Access Control in tooljet/tooljetEPSS 1.1%CVE-2022-2037CRITICALExcessive Attack Surface in tooljet/tooljetEPSS 1.1%CVE-2022-3348MEDIUMExposure of Sensitive Information to an Unauthorized Actor in tooljet/tooljetEPSS 0.9%CVE-2022-3422CRITICALImproper Privilege Management in tooljet/tooljetEPSS 0.8%CVE-2022-4111MEDIUMImproper Validation of Specified Quantity in Input in tooljet/tooljetEPSS 0.8%CVE-2022-3019HIGHImproper Access Control in tooljet/tooljetEPSS 0.7%CVE-2022-23068MEDIUMToolJet - HTML Injection in Invite New UserEPSS 0.6%CVE-2026-55413CRITICALToolJet - Marketplace Plugin Poisoning Enables Instance-Wide Remote Code ExecutionEPSS 0.3%CVE-2026-55412HIGHToolJet Cloud - SSRF to Azure Cloud Infrastructure CompromiseEPSS 0.2%CVE-2026-54344MEDIUMToolJet GitHub Actions comment body shell injection exposes deployment secretsEPSS 0.2%CVE-2026-55411MEDIUMToolJet: Cross-tenant credential decryption (IDOR) in POST /api/data-sources/decrypt — any authenticated user can decrypt any organization's data-source secretsEPSS 0.1%