Vulnerabilidades en budibase
81 resultadosAnálisis Vexday
Budibase apresenta footprint de risco mínimo com apenas 1 CVE registrado na base, sem incidentes sob ataque ativo ou vulnerabilidades críticas. A fraqueza identificada (CWE-913 - Improper Control of Dynamically-Managed Code Execution) é de severidade moderada e não há registros recentes de novas exposições, indicando perfil de risco baixo no curto prazo.
CVE-2026-73308MEDIUMBudibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other BuildersEPSS 0.4%CVE-2026-82245HIGHBudibase before 3.41.3 Missing Authorization License ManagementEPSS 0.4%CVE-2026-33226HIGHBudibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query PreviewEPSS 0.4%CVE-2026-82239HIGHBudibase before 3.41.3 Authorization Bypass via datasources/queryEPSS 0.4%CVE-2026-48149HIGHBudibase: Stored XSS in Text component: BASIC users execute JS in admin session via MarkdownViewer innerHTML + CDN+srcdoc CSP bypassEPSS 0.4%CVE-2026-25737HIGHBudibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS)EPSS 0.4%CVE-2026-48151HIGHBudibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schemaEPSS 0.4%CVE-2026-72855HIGHBudibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and RESTEPSS 0.4%CVE-2026-42239HIGHBudibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeoverEPSS 0.4%CVE-2026-46427HIGHBudibase: Snowflake private key returned unmasked from datasource API to BASIC usersEPSS 0.4%CVE-2026-82240HIGHBudibase before 3.41.3 Privilege Escalation via User Update APIEPSS 0.4%CVE-2026-45061HIGHBudibase: SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)EPSS 0.4%CVE-2026-45548HIGHBudibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist ValidationEPSS 0.4%CVE-2026-72857HIGHBudibase before 3.40.0 Credential Exposure via STRING FieldsEPSS 0.4%CVE-2026-45715HIGHBudibase: SSRF Bypass via HTTP Redirect in REST Datasource IntegrationEPSS 0.4%CVE-2026-54356HIGHBudibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`EPSS 0.4%CVE-2026-48148MEDIUMBudibase: Unvalidated VectorDB Host Parameter Enables SSRFEPSS 0.4%CVE-2026-72853HIGHBudibase before 3.40.0 SQL Injection via Oracle connectorEPSS 0.3%CVE-2026-73617HIGHBudibase before 3.40.0 NoSQL Injection via MongoDB datasourceEPSS 0.3%CVE-2026-73301MEDIUMBudibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappingsEPSS 0.3%