Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

nocodb — Vulnerabilities & Security Advisories 58

Browse all 58 CVE security advisories affecting nocodb. AI-powered Chinese analysis, POCs, and references for each vulnerability.

NocoDB is an open-source platform that transforms relational databases into intuitive spreadsheet interfaces, enabling rapid application development without extensive coding. Despite its utility, the software has accumulated twenty-nine recorded Common Vulnerabilities and Exposures (CVEs), indicating significant historical security challenges. Analysis of these flaws reveals a prevalence of critical vulnerability classes, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Privilege Escalation. These issues often stem from insufficient input validation and improper access control mechanisms within the application’s API layers. While no single catastrophic data breach has been widely publicized as a defining incident, the sheer volume of disclosed CVEs suggests systemic weaknesses in the codebase’s security architecture. Users are advised to prioritize strict patch management and rigorous environment hardening to mitigate risks associated with these known exploitable conditions.

Top products by nocodb: nocodb nocodb/nocodb
CVE ID Title CVSS Severity Published
CVE-2026-28399 NocoDB: SQL Injection via DATEADD Formula — nocodb CWE-89 8.8AI High AI 2026-03-02
CVE-2026-28398 NocoDB: Stored Cross-Site Scripting via Comments and Rich Text Cells — nocodb CWE-79 5.4AI Medium AI 2026-03-02
CVE-2026-28397 NocoDB: Stored Cross-Site Scripting via Comments — nocodb CWE-79 5.4AI Medium AI 2026-03-02
CVE-2026-28396 NocoDB: Refresh Tokens Not Revoked on Password Reset — nocodb CWE-613 7.1AI High AI 2026-03-02
CVE-2026-28361 NocoDB: Missing Ownership Validation in MCP Token Operations — nocodb CWE-639 8.3AI High AI 2026-03-02
CVE-2026-28360 NocoDB: Plaintext Storage of Shared View Passwords — nocodb CWE-256 6.5AI Medium AI 2026-03-02
CVE-2026-28359 NocoDB: Stored Cross-Site Scripting via Rich Text Field — nocodb CWE-79 5.4AI Medium AI 2026-03-02
CVE-2026-28358 NocoDB: User Enumeration via Password Reset Endpoint — nocodb CWE-204 5.3AI Medium AI 2026-03-02
CVE-2026-28357 NocoDB: Stored Cross-Site Scripting via Formula Cell — nocodb CWE-79 5.4AI Medium AI 2026-03-02
CVE-2026-24769 NocoDB Vulnerable to Stored Cross-Site Scripting via SVG upload — nocodb CWE-79 5.4AI Medium AI 2026-01-28
CVE-2026-24768 NocoDB has Unvalidated Redirect in Login Flow via continueAfterSignIn Parameter — nocodb CWE-601 6.1AI Medium AI 2026-01-28
CVE-2026-24767 NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality — nocodb CWE-918 4.9 Medium 2026-01-28
CVE-2026-24766 NocoDB Vulnerable to Prototype Pollution in Connection Test Endpoint, Leading to DoS — nocodb CWE-1321 4.9 Medium 2026-01-28
CVE-2025-27506 NocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password Page — nocodb CWE-79 5.4 Medium 2025-03-06
CVE-2023-49781 NocoDB Vulnerable to Stored Cross-Site Scripting in Formula.vue — nocodb CWE-79 7.3 High 2024-05-13
CVE-2023-50718 NocoDB SQL Injection vulnerability — nocodb CWE-89 6.5 Medium 2024-05-13
CVE-2023-50717 NocoDB Allows Preview of File with Dangerous Content — nocodb CWE-434 5.7 Medium 2024-05-13
CVE-2023-43794 SQL Injection in nocodb — nocodb CWE-89 6.5 Medium 2023-10-17
CVE-2023-5104 Improper Input Validation in nocodb/nocodb — nocodb/nocodb CWE-20 9.8 - 2023-09-21
CVE-2022-3423 Allocation of Resources Without Limits or Throttling in nocodb/nocodb — nocodb/nocodb CWE-770 7.3 High 2022-10-07
CVE-2022-2339 Server-Side Request Forgery (SSRF) in nocodb/nocodb — nocodb/nocodb CWE-918 6.5 - 2022-07-07
CVE-2022-2079 Cross-site Scripting (XSS) - Stored in nocodb/nocodb — nocodb/nocodb CWE-79 5.4 - 2022-06-14
CVE-2022-2064 Insufficient Session Expiration in nocodb/nocodb — nocodb/nocodb CWE-613 9.8 - 2022-06-13
CVE-2022-2063 Improper Privilege Management in nocodb/nocodb — nocodb/nocodb CWE-269 8.8 - 2022-06-13
CVE-2022-2062 Generation of Error Message Containing Sensitive Information in nocodb/nocodb — nocodb/nocodb CWE-209 7.5 - 2022-06-13
CVE-2022-2022 Cross-site Scripting (XSS) - Stored in nocodb/nocodb — nocodb/nocodb CWE-79 5.4 - 2022-06-07
CVE-2022-22121 NocoDB - CSV Injection in User Management — nocodb CWE-1236 8.0 High 2022-01-10
CVE-2022-22120 NocoDB - Observable Discrepancy in the password-reset feature — nocodb CWE-203 5.3 Medium 2022-01-10

This page lists every published CVE security advisory associated with nocodb. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.