Known Vulnerabilities for Server by Budibase
Listed below are 10 of the newest known vulnerabilities associated with "Server" by "Budibase".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100720 json | Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticat... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100717 json | froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and l... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100716 json | Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to v... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100708 json | Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in th... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100705 json | Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.16... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100698 json | Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functi... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100697 json | Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) ... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100696 json | Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional El... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100695 json | Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated ... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100688 json | Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appI... | Not Provided | 2026-09-26 | 2026-09-26 |