Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

nocodb — Vulnerabilities & Security Advisories 58

Browse all 58 CVE security advisories affecting nocodb. AI-powered Chinese analysis, POCs, and references for each vulnerability.

NocoDB is an open-source platform that transforms relational databases into intuitive spreadsheet interfaces, enabling rapid application development without extensive coding. Despite its utility, the software has accumulated twenty-nine recorded Common Vulnerabilities and Exposures (CVEs), indicating significant historical security challenges. Analysis of these flaws reveals a prevalence of critical vulnerability classes, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Privilege Escalation. These issues often stem from insufficient input validation and improper access control mechanisms within the application’s API layers. While no single catastrophic data breach has been widely publicized as a defining incident, the sheer volume of disclosed CVEs suggests systemic weaknesses in the codebase’s security architecture. Users are advised to prioritize strict patch management and rigorous environment hardening to mitigate risks associated with these known exploitable conditions.

Top products by nocodb: nocodb nocodb/nocodb
CVE ID Title CVSS Severity Published
CVE-2026-46547 NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL — nocodb CWE-79 6.1 Medium 2026-06-23
CVE-2026-46548 NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams) — nocodb CWE-918 4.3 Medium 2026-06-23
CVE-2026-46549 NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation — nocodb CWE-863 2.0 Low 2026-06-23
CVE-2026-46550 NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags — nocodb CWE-614 5.4 Medium 2026-06-23
CVE-2026-46552 NocoDB: Shared-base link access can invite arbitrary users as persistent base members — nocodb CWE-285 5.8 Medium 2026-06-23
CVE-2026-46553 NocoDB: Attachment Size Limit Bypass via Upload-by-URL — nocodb CWE-770 - - 2026-06-23
CVE-2026-47375 NocoDB: Postgres SQL Injection in Formula `ARRAYSORT` — nocodb CWE-89 6.0 Medium 2026-06-23
CVE-2026-47376 NocoDB: Reflected Cross-Site Scripting via Password Reset Token — nocodb CWE-79 - - 2026-06-23
CVE-2026-47377 NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin — nocodb CWE-601 - - 2026-06-23
CVE-2026-47378 NocoDB: Hidden Column Exposure in Public Shared View Endpoints — nocodb CWE-639 - - 2026-06-23
CVE-2026-47380 NocoDB: User Enumeration via Sign-In Timing — nocodb CWE-208 - - 2026-06-23
CVE-2026-46551 NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion — nocodb CWE-770 6.5 Medium 2026-06-23
CVE-2026-46554 NocoDB: Stale Auth Cache After API Token Deletion — nocodb CWE-613 - - 2026-06-23
CVE-2026-47382 NocoDB: Server-Side Request Forgery via Database Connection Host — nocodb CWE-918 - - 2026-06-23
CVE-2026-47279 NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints — nocodb CWE-284 - - 2026-06-23
CVE-2026-47379 NocoDB: Plaintext Password Comparison in Shared Views — nocodb CWE-200 - - 2026-06-23
CVE-2026-47381 NocoDB: Cross-Workspace Integration Use in Connection Test — nocodb CWE-290 - - 2026-06-23
CVE-2026-47383 NocoDB: Stored Cross-Site Scripting via Row Comments — nocodb CWE-79 - - 2026-06-23
CVE-2026-47384 NocoDB: SQL Injection via Column Title in Bulk GroupBy — nocodb CWE-89 - - 2026-06-23
CVE-2026-47385 NocoDB: Path Traversal via SQLite Source Filename — nocodb CWE-22 - - 2026-06-23
CVE-2026-47386 NocoDB: OAuth Authorization Code Race Condition — nocodb CWE-362 - - 2026-06-23
CVE-2026-47387 NocoDB: Stored Cross-Site Scripting via Form View Redirect URL — nocodb CWE-79 - - 2026-06-23
CVE-2026-47388 NocoDB: Missing Ownership Check in MCP Attachment Read — nocodb CWE-639 - - 2026-06-23
CVE-2026-53926 NocoDB: OAuth Tokens Persist Through Security Events — nocodb CWE-613 - - 2026-06-23
CVE-2026-53927 NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL — nocodb CWE-918 - - 2026-06-23
CVE-2026-53928 NocoDB: Refresh Tokens Persist Through Password Recovery — nocodb CWE-613 - - 2026-06-23
CVE-2026-53929 NocoDB: Stored Cross-Site Scripting via Secure Attachment — nocodb CWE-79 - - 2026-06-23
CVE-2026-53930 NocoDB: Server-Side Request Forgery via Base Migration URL — nocodb CWE-918 - - 2026-06-23
CVE-2026-53931 NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint — nocodb CWE-441 - - 2026-06-23
CVE-2026-28401 NocoDB: Stored Cross-Site Scripting via Rich Text Cells — nocodb CWE-79 5.4AI Medium AI 2026-03-02

This page lists every published CVE security advisory associated with nocodb. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.