Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

nocodb — Vulnerabilities & Security Advisories 50

All 50 CVE vulnerabilities found in nocodb, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting NocoDB, an open-source database tool. It collects publicly disclosed weaknesses and related advisories spanning the product's operational history. Readers can use this collection to track vendor-issued security updates, analyze specific weakness categories such as injection flaws or access control issues, and review the chronological evolution of security patches. The entries are organized to support trend analysis and risk assessment for organizations deploying NocoDB in production environments.

Vendor: nocodb

CVE ID Title CVSS Severity Published
CVE-2026-46547 NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL CWE-79 6.1 Medium 2026-06-23
CVE-2026-46548 NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams) CWE-918 4.3 Medium 2026-06-23
CVE-2026-46549 NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation CWE-863 2.0 Low 2026-06-23
CVE-2026-46550 NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags CWE-614 5.4 Medium 2026-06-23
CVE-2026-46552 NocoDB: Shared-base link access can invite arbitrary users as persistent base members CWE-285 5.8 Medium 2026-06-23
CVE-2026-46553 NocoDB: Attachment Size Limit Bypass via Upload-by-URL CWE-770 - - 2026-06-23
CVE-2026-47375 NocoDB: Postgres SQL Injection in Formula `ARRAYSORT` CWE-89 6.0 Medium 2026-06-23
CVE-2026-47376 NocoDB: Reflected Cross-Site Scripting via Password Reset Token CWE-79 - - 2026-06-23
CVE-2026-47377 NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin CWE-601 - - 2026-06-23
CVE-2026-47378 NocoDB: Hidden Column Exposure in Public Shared View Endpoints CWE-639 - - 2026-06-23
CVE-2026-47380 NocoDB: User Enumeration via Sign-In Timing CWE-208 - - 2026-06-23
CVE-2026-46551 NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion CWE-770 6.5 Medium 2026-06-23
CVE-2026-46554 NocoDB: Stale Auth Cache After API Token Deletion CWE-613 - - 2026-06-23
CVE-2026-47382 NocoDB: Server-Side Request Forgery via Database Connection Host CWE-918 - - 2026-06-23
CVE-2026-47279 NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints CWE-284 - - 2026-06-23
CVE-2026-47379 NocoDB: Plaintext Password Comparison in Shared Views CWE-200 - - 2026-06-23
CVE-2026-47381 NocoDB: Cross-Workspace Integration Use in Connection Test CWE-290 - - 2026-06-23
CVE-2026-47383 NocoDB: Stored Cross-Site Scripting via Row Comments CWE-79 - - 2026-06-23
CVE-2026-47384 NocoDB: SQL Injection via Column Title in Bulk GroupBy CWE-89 - - 2026-06-23
CVE-2026-47385 NocoDB: Path Traversal via SQLite Source Filename CWE-22 - - 2026-06-23
CVE-2026-47386 NocoDB: OAuth Authorization Code Race Condition CWE-362 - - 2026-06-23
CVE-2026-47387 NocoDB: Stored Cross-Site Scripting via Form View Redirect URL CWE-79 - - 2026-06-23
CVE-2026-47388 NocoDB: Missing Ownership Check in MCP Attachment Read CWE-639 - - 2026-06-23
CVE-2026-53926 NocoDB: OAuth Tokens Persist Through Security Events CWE-613 - - 2026-06-23
CVE-2026-53927 NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL CWE-918 - - 2026-06-23
CVE-2026-53928 NocoDB: Refresh Tokens Persist Through Password Recovery CWE-613 - - 2026-06-23
CVE-2026-53929 NocoDB: Stored Cross-Site Scripting via Secure Attachment CWE-79 - - 2026-06-23
CVE-2026-53930 NocoDB: Server-Side Request Forgery via Base Migration URL CWE-918 - - 2026-06-23
CVE-2026-53931 NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint CWE-441 - - 2026-06-23
CVE-2026-28401 NocoDB: Stored Cross-Site Scripting via Rich Text Cells CWE-79 5.4AI Medium AI 2026-03-02

All 50 known CVE vulnerabilities affecting nocodb with full Chinese analysis, references, and POCs where available.