Vulnerabilidades em budibase

81 resultados
Análise Vexday

Budibase apresenta footprint de risco mínimo com apenas 1 CVE registrado na base, sem incidentes sob ataque ativo ou vulnerabilidades críticas. A fraqueza identificada (CWE-913 - Improper Control of Dynamically-Managed Code Execution) é de severidade moderada e não há registros recentes de novas exposições, indicando perfil de risco baixo no curto prazo.

CVE-2026-72856HIGHBudibase before 3.40.0 Authentication Bypass via Tenant Owner EmailEPSS 0.5%CVE-2026-48150CRITICALBudibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assignEPSS 0.5%CVE-2026-45716HIGHBudibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP ConfigurationEPSS 0.5%CVE-2026-25044HIGHBudibase: Command Injection in Bash Automation StepEPSS 0.5%CVE-2026-35219HIGHBudibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP BlacklistEPSS 0.5%CVE-2026-54351HIGHBudibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId OverrideEPSS 0.5%CVE-2026-73408HIGHBudibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database ConnectorEPSS 0.5%CVE-2026-35218HIGHBudibase: Stored XSS via unsanitized entity names rendered with {@html} in Builder Command PaletteEPSS 0.4%CVE-2026-64657HIGHBudibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQLEPSS 0.4%CVE-2026-45717HIGHBudibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL.EPSS 0.4%CVE-2026-46425CRITICALBudibase: SCIM endpoints lack role-based authorization, BASIC users CRUD tenant usersEPSS 0.4%CVE-2026-48152HIGHBudibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URLEPSS 0.4%CVE-2026-73306MEDIUMBudibase: Account Enumeration via Login Lockout Response DifferentialEPSS 0.4%CVE-2026-31818CRITICALBudibase: Server-Side Request Forgery via REST Connector with Empty Default BlacklistEPSS 0.4%CVE-2026-73302CRITICALBudibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verifiedEPSS 0.4%CVE-2026-73307MEDIUMBudibase: SSRF via bare fetch() in uploadUrl during AI table generationEPSS 0.4%CVE-2026-45719MEDIUMBudibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views APIEPSS 0.4%CVE-2026-72851CRITICALBudibase before 3.40.0 SQL Injection via Unauthenticated WebhookEPSS 0.4%CVE-2026-67311HIGHBudibase before 3.38.1 SSRF Blacklist Bypass via HTTP RedirectEPSS 0.4%CVE-2026-50137HIGHBudibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentialsEPSS 0.4%