Known Vulnerabilities for products from Budibase
Listed below are 18 of the newest known vulnerabilities associated with the vendor "Budibase".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103757 json | Not Provided | 2026-10-01 | 2026-10-01 | |
| CVE-2026-100688 json | Not Provided | 2026-09-26 | 2026-10-08 | |
| CVE-2026-100687 json | Not Provided | 2026-09-26 | 2026-10-08 | |
| CVE-2026-100686 json | Not Provided | 2026-09-26 | 2026-10-08 | |
| CVE-2026-100685 json | Not Provided | 2026-09-26 | 2026-10-08 | |
| CVE-2026-100684 json | Not Provided | 2026-09-26 | 2026-10-08 | |
| CVE-2026-100683 json | Not Provided | 2026-09-26 | 2026-10-08 | |
| CVE-2026-100682 json | Not Provided | 2026-09-26 | 2026-10-08 | |
| CVE-2026-100681 json | Not Provided | 2026-09-26 | 2026-10-08 | |
| CVE-2026-100680 json | Not Provided | 2026-09-26 | 2026-10-08 | |
| CVE-2026-54353 json | Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Bud... | Not Provided | 2026-06-26 | 2026-06-30 |
| CVE-2026-54352 json | Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/... | Not Provided | 2026-06-26 | 2026-06-30 |
| CVE-2026-54351 json | Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessibl... | Not Provided | 2026-06-26 | 2026-06-30 |
| CVE-2026-54350 json | Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app rea... | Not Provided | 2026-06-26 | 2026-06-30 |
| CVE-2026-50137 json | Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace i... | Not Provided | 2026-06-26 | 2026-06-30 |
| CVE-2026-50136 json | Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint tha... | Not Provided | 2026-06-26 | 2026-06-30 |
| CVE-2026-50132 json | Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public end... | Not Provided | 2026-06-26 | 2026-06-30 |
| CVE-2026-42239 json | Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session t... | Not Provided | 2026-05-07 | 2026-06-04 |
| CVE-2026-41428 json | Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressio... | Not Provided | 2026-04-24 | 2026-04-28 |
| CVE-2026-35218 json | Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity name... | Not Provided | 2026-04-03 | 2026-04-08 |