Vulnerabilidades en tooljet

20 resultados
Análisis Vexday

ToolJet apresenta 6 vulnerabilidades catalogadas, sendo 3 de severidade crítica, mas nenhuma sob exploração ativa documentada. A fraqueza predominante (CWE-284 - controle de acesso impróprio) aponta para problemas estruturais de autorização que podem ser explorados sem necessidade de patch zero-day. Não há atividade de exploração recente, reduzindo a urgência imediata, porém o volume de críticas exige atenção na priorização de remediação.

CVE-2022-23067HIGHToolJet - Token Leakage via Referer HeaderEPSS 1.3%CVE-2022-2037CRITICALExcessive Attack Surface in tooljet/tooljetEPSS 1.1%CVE-2022-2631CRITICALImproper Access Control in tooljet/tooljetEPSS 1.1%CVE-2022-3019HIGHImproper Access Control in tooljet/tooljetEPSS 0.9%CVE-2022-3348MEDIUMExposure of Sensitive Information to an Unauthorized Actor in tooljet/tooljetEPSS 0.9%CVE-2022-3422CRITICALImproper Privilege Management in tooljet/tooljetEPSS 0.9%CVE-2022-4111MEDIUMImproper Validation of Specified Quantity in Input in tooljet/tooljetEPSS 0.8%CVE-2022-23068MEDIUMToolJet - HTML Injection in Invite New UserEPSS 0.6%CVE-2026-55413CRITICALToolJet - Marketplace Plugin Poisoning Enables Instance-Wide Remote Code ExecutionEPSS 0.4%CVE-2026-54344MEDIUMToolJet GitHub Actions comment body shell injection exposes deployment secretsEPSS 0.3%CVE-2026-55412HIGHToolJet Cloud - SSRF to Azure Cloud Infrastructure CompromiseEPSS 0.3%CVE-2026-73068MEDIUMToolJet: Cross-tenant Broken Access Control in ToolJet Database (tooljet-db): any authenticated user can read and write another organization's tablesEPSS 0.3%CVE-2026-82872HIGHToolJet before v3.16.208 Cross-Workspace Authorization BypassEPSS 0.3%CVE-2026-82874CRITICALToolJet before v3.16.208 Cross-Tenant Authorization Bypass via tooljet-dbEPSS 0.2%CVE-2026-82869HIGHToolJet Database before v3.16.44 Privilege Escalation via join_tablesEPSS 0.2%CVE-2026-82871HIGHToolJet before v3.16.208 Cross-Organization Data Read via Database RoutesEPSS 0.2%CVE-2026-82870HIGHToolJet before v3.16.208 Cross-Tenant Database ManipulationEPSS 0.2%CVE-2026-55411MEDIUMToolJet: Cross-tenant credential decryption (IDOR) in POST /api/data-sources/decrypt — any authenticated user can decrypt any organization's data-source secretsEPSS 0.2%CVE-2026-82873MEDIUMToolJet through 3.0.0-ee-beta.2 Cross-workspace Schema Disclosure via ExportEPSS 0.2%CVE-2026-82875MEDIUMToolJet before v3.16.208 Authorization Bypass via organizationIdEPSS 0.1%