Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

budibase — Vulnerabilities & Security Advisories 91

Browse all 91 CVE security advisories affecting budibase. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Budibase serves as a low-code platform enabling rapid development of internal tools and business applications. Historically, the platform has been susceptible to multiple critical vulnerabilities, including remote code execution, cross-site scripting, and privilege escalation flaws, contributing to its 18 recorded CVEs. Security researchers have identified authentication bypasses and insecure default configurations as recurring issues. While no major public security incidents have been widely documented, the significant CVE count suggests potential risks for organizations implementing Budibase without rigorous hardening. Users should prioritize applying security patches and implementing additional safeguards when deploying this platform for business-critical applications.

CVE ID Title CVSS Severity Published
CVE-2026-103757 Budibase before 3.41.0 SSRF via uploadUrl in AI Table Generation — budibase CWE-918 7.7 High 2026-10-01
CVE-2026-100688 Budibase server before 3.45.0 Cross-Tenant Information Disclosure — server CWE-639 6.5 Medium 2026-09-26
CVE-2026-100686 Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:groupId/apps — server CWE-269 8.1 High 2026-09-26
CVE-2026-100687 Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast — server CWE-200 5.5 Medium 2026-09-26
CVE-2026-100685 Budibase before 3.45.0 Information Disclosure via Chat Links — server CWE-863 7.7 High 2026-09-26
CVE-2026-100683 Budibase before 3.45.0 SQL Injection via column-rename DDL — server CWE-89 8.0 High 2026-09-26
CVE-2026-100684 Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC — server CWE-287 8.1 High 2026-09-26
CVE-2026-100682 Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink — server CWE-22 8.8 High 2026-09-26
CVE-2026-100681 Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook — server CWE-918 5.4 Medium 2026-09-26
CVE-2026-100680 Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import — server CWE-200 8.1 High 2026-09-26
CVE-2026-82246 Budibase Server before 3.41.3 SSRF via Query Import — server CWE-918 7.1 High 2026-08-28
CVE-2026-82245 Budibase before 3.41.3 Missing Authorization License Management — server CWE-862 8.1 High 2026-08-28
CVE-2026-82243 Budibase Server before 3.41.3 SSRF with Credential Leakage — server CWE-918 7.6 High 2026-08-28
CVE-2026-82244 Budibase before 3.41.3 Remote Code Execution via Plugin eval() — server CWE-94 9.1 Critical 2026-08-28
CVE-2026-82242 Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization — server CWE-862 7.7 High 2026-08-28
CVE-2026-82241 Budibase backend-core SSRF via incomplete default blacklist — server CWE-918 7.1 High 2026-08-28
CVE-2026-82240 Budibase before 3.41.3 Privilege Escalation via User Update API — server CWE-862 8.1 High 2026-08-28
CVE-2026-82239 Budibase before 3.41.3 Authorization Bypass via datasources/query — server CWE-862 8.1 High 2026-08-28
CVE-2026-54356 Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url` — budibase CWE-862 7.1 High 2026-08-17
CVE-2026-35219 Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist — budibase CWE-918 7.1 High 2026-08-17
CVE-2026-73410 Budibase: SSRF via DNS rebinding in the REST datasource integration — budibase CWE-367 8.5 High 2026-08-17
CVE-2026-64657 Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL — budibase CWE-89 8.4 High 2026-08-17
CVE-2026-72859 Budibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URL — server CWE-863 7.7 High 2026-08-14
CVE-2026-73305 Budibase: Privilege escalation via public role assignment API missing app-level authorization — budibase CWE-269 8.8 High 2026-08-13
CVE-2026-73304 Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users — budibase CWE-200 4.9 Medium 2026-08-13
CVE-2026-73408 Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector — budibase CWE-89 7.6 High 2026-08-13
CVE-2026-73302 Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified — budibase CWE-287 9.0 Critical 2026-08-13
CVE-2026-72857 Budibase before 3.40.0 Credential Exposure via STRING Fields — budibase CWE-522 7.7 High 2026-08-13
CVE-2026-72855 Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST — server CWE-918 8.5 High 2026-08-13
CVE-2026-72856 Budibase before 3.40.0 Authentication Bypass via Tenant Owner Email — budibase CWE-640 8.1 High 2026-08-13

This page lists every published CVE security advisory associated with budibase. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.