Vulnerabilidades em budibase
81 resultadosAnálise Vexday
Budibase apresenta footprint de risco mínimo com apenas 1 CVE registrado na base, sem incidentes sob ataque ativo ou vulnerabilidades críticas. A fraqueza identificada (CWE-913 - Improper Control of Dynamically-Managed Code Execution) é de severidade moderada e não há registros recentes de novas exposições, indicando perfil de risco baixo no curto prazo.
CVE-2026-48146HIGHBudibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist ProtectionEPSS 0.3%CVE-2026-82242HIGHBudibase before 3.41.3 Cross-Application Resource Injection via Missing AuthorizationEPSS 0.3%CVE-2026-82243HIGHBudibase Server before 3.41.3 SSRF with Credential LeakageEPSS 0.3%CVE-2026-73409MEDIUMBudibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFileEPSS 0.3%CVE-2026-30240CRITICALBudibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All Environment SecretsEPSS 0.3%CVE-2026-72859HIGHBudibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URLEPSS 0.3%CVE-2026-73303HIGHBudibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)EPSS 0.3%CVE-2026-82241HIGHBudibase backend-core SSRF via incomplete default blacklistEPSS 0.3%CVE-2026-82246HIGHBudibase Server before 3.41.3 SSRF via Query ImportEPSS 0.3%CVE-2026-25043MEDIUMBudibase: Unauthenticated Password Reset Endpoint Lacks Rate Limiting, Enabling Email FloodingEPSS 0.3%CVE-2026-46426HIGHBudibase: Unrestricted Upload of File with Dangerous TypeEPSS 0.3%CVE-2026-25045HIGHBudibase Critical Privilege Escalation & IDOR via Missing RBAC on User Role Management (Creator-Role)EPSS 0.3%CVE-2026-48153HIGHBudibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadataEPSS 0.3%CVE-2026-50136HIGHBudibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentialsEPSS 0.3%CVE-2026-73410HIGHBudibase: SSRF via DNS rebinding in the REST datasource integrationEPSS 0.3%CVE-2026-46424MEDIUMBudibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 HourEPSS 0.2%CVE-2026-45718MEDIUMBudibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope RowsEPSS 0.2%CVE-2026-54353HIGHBudibase: Potential SSRF DNS rebinding bypass in outbound fetch validationEPSS 0.2%CVE-2026-50132HIGHBudibase: Chat Identity Link Hijacking via Missing Consent & CSRF — Account Impersonation in BudibaseEPSS 0.2%CVE-2026-48147MEDIUMBudibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase WorkerEPSS 0.2%