Known Vulnerabilities for Budibase by Budibase
Listed below are 10 of the newest known vulnerabilities associated with "Budibase" by "Budibase".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82246 json | Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82245 json | Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated ... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82244 json | Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated ad... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82243 json | Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that all... | Not Provided | 2026-08-28 | 2026-08-31 |
| CVE-2026-82242 json | Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint t... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82241 json | Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/1... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82240 json | Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, ... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82239 json | Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-73618 json | Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-sup... | Not Provided | 2026-08-13 | 2026-08-13 |
| CVE-2026-73617 json | Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplied par... | Not Provided | 2026-08-13 | 2026-08-14 |