Vulnerabilidades en budibase
46 resultadosAnálisis Vexday
Budibase apresenta footprint de risco mínimo com apenas 1 CVE registrado na base, sem incidentes sob ataque ativo ou vulnerabilidades críticas. A fraqueza identificada (CWE-913 - Improper Control of Dynamically-Managed Code Execution) é de severidade moderada e não há registros recentes de novas exposições, indicando perfil de risco baixo no curto prazo.
CVE-2026-48153HIGHBudibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadataEPSS 0.2%CVE-2026-46424MEDIUMBudibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 HourEPSS 0.2%CVE-2026-54353HIGHBudibase: Potential SSRF DNS rebinding bypass in outbound fetch validationEPSS 0.2%CVE-2026-50132HIGHBudibase: Chat Identity Link Hijacking via Missing Consent & CSRF — Account Impersonation in BudibaseEPSS 0.2%CVE-2026-45718MEDIUMBudibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope RowsEPSS 0.1%CVE-2026-48147MEDIUMBudibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase WorkerEPSS 0.1%