Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license ke...
Budibase CVEs
32 high and critical vulnerabilities covered by CVE Brief since 2026-02-25, each with independent analyst commentary.
← All vendors RSS feed Watch this vendorProfile
Last 12 months
32 CVEs in the last 12 months
Products
- budibase25
- server7
2 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users t...
Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated...
Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated...
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to...
Budibase is an open-source low-code platform
Budibase is an open-source low-code platform
Budibase versions 3
Budibase server versions before 3.40.0 contain an unauthenticated SQL injection vulnerability in webhook-triggered automations, allowing remote attack...
Budibase is an open-source low-code platform
Budibase is an open-source low-code platform
An improper path validation vulnerability in the Budibase PWA upload process allows authenticated builders to perform arbitrary file reads on the serv...
Budibase is an open-source low-code platform
An unauthenticated injection vulnerability in Budibase allows remote attackers to read or modify arbitrary documents in connected databases via malici...
Budibase is an open-source low-code platform
Budibase is an open-source low-code platform
Budibase is an open-source low-code platform
Budibase is an open-source low-code platform
Budibase contains an authorization bypass vulnerability in the SCIM API, allowing authenticated users to perform unauthorized CRUD operations on all u...
Budibase is an open-source low-code platform
Budibase is an open-source low-code platform
Budibase is an open-source low-code platform
Budibase contains an authentication bypass vulnerability where unanchored regular expressions allow attackers to access protected endpoints via crafte...
Budibase is an open-source low-code platform
Budibase versions prior to 3.33.4 contain an unauthenticated Remote Code Execution (RCE) flaw. Attackers can trigger Bash-based automations via a publ...
Budibase is an open-source low-code platform
Budibase is a low code platform for creating internal tools, workflows, and admin panels
Budibase versions prior to 3.33.4 are vulnerable to Server-Side Request Forgery (SSRF). The SSRF protection is ineffective by default, allowing unauth...
A regex bypass in Budibase's middleware allows unauthenticated attackers to skip all authentication and authorization checks by appending a webhook pa...
A path traversal vulnerability in Budibase's PWA ZIP processing allows authenticated builders to exfiltrate sensitive server files, including environm...
Budibase Cloud suffers from an unsafe eval() vulnerability in its view filtering, allowing authenticated users to execute arbitrary JavaScript and acc...
Budibase is a low code platform for creating internal tools, workflows, and admin panels