Browse all 69 CVE security advisories affecting Budibase. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Budibase serves as a low-code platform enabling rapid development of internal tools and business applications. Historically, the platform has been susceptible to multiple critical vulnerabilities, including remote code execution, cross-site scripting, and privilege escalation flaws, contributing to its 18 recorded CVEs. Security researchers have identified authentication bypasses and insecure default configurations as recurring issues. While no major public security incidents have been widely documented, the significant CVE count suggests potential risks for organizations implementing Budibase without rigorous hardening. Users should prioritize applying security patches and implementing additional safeguards when deploying this platform for business-critical applications.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-72859 | Budibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URL — serverCWE-863 | 7.7 | High | 2026-08-14 |
| CVE-2026-72855 | Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST — serverCWE-918 | 8.5 | High | 2026-08-13 |
| CVE-2026-72851 | Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook — serverCWE-89 | 10.0 | Critical | 2026-08-13 |
| CVE-2026-72850 | Budibase before 3.40.0 Arbitrary File Write via Path Traversal — serverCWE-22 | 9.1 | Critical | 2026-08-13 |
| CVE-2026-72849 | Budibase before 3.40.0 Identity Confusion via Chat-Link Handoff CSRF — serverCWE-352 | 7.7 | High | 2026-08-13 |
| CVE-2026-73618 | Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter — serverCWE-943 | 8.3 | High | 2026-08-13 |
| CVE-2026-73617 | Budibase before 3.40.0 NoSQL Injection via MongoDB datasource — serverCWE-943 | 7.1 | High | 2026-08-13 |
This page lists every published CVE security advisory associated with Budibase. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.