32 Total CVEs
32 AI Analyzed
0 CISA KEV
10 Critical

Profile

0% ended up actively exploited 0 of 32 added to CISA KEV
31% rated critical (CVSS 9.0+) 10 critical, 22 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

32 CVEs in the last 12 months

Products

  • budibase25
  • server7

2 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-32 of 32 CVEs
CVE-2026-82245
Analyzed
8.1
Budibase server

Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license ke...

2026-08-30
Full analysis →
CVE-2026-82243
Analyzed
7.6
Budibase server

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users t...

2026-08-30
Full analysis →
CVE-2026-82242
Analyzed
7.7
Budibase server

Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated...

2026-08-30
Full analysis →
CVE-2026-82240
Analyzed
8.1
Budibase server

Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated...

2026-08-30
Full analysis →
CVE-2026-82239
Analyzed
8.1
Budibase server

Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to...

2026-08-30
Full analysis →
CVE-2026-72851
Analyzed
10
Budibase server

Budibase server versions before 3.40.0 contain an unauthenticated SQL injection vulnerability in webhook-triggered automations, allowing remote attack...

2026-08-14
Full analysis →
CVE-2026-54352
Analyzed
9.6
Budibase budibase

An improper path validation vulnerability in the Budibase PWA upload process allows authenticated builders to perform arbitrary file reads on the serv...

2026-06-27
Full analysis →
CVE-2026-54350
Analyzed
10
Budibase budibase

An unauthenticated injection vulnerability in Budibase allows remote attackers to read or modify arbitrary documents in connected databases via malici...

2026-06-27
Full analysis →
CVE-2026-46425
Analyzed
9.9
Budibase budibase

Budibase contains an authorization bypass vulnerability in the SCIM API, allowing authenticated users to perform unauthorized CRUD operations on all u...

2026-05-28
Full analysis →
CVE-2026-41428
Analyzed
9.1
Budibase budibase

Budibase contains an authentication bypass vulnerability where unanchored regular expressions allow attackers to access protected endpoints via crafte...

2026-04-25
Full analysis →
CVE-2026-35216
Analyzed
9
Budibase budibase

Budibase versions prior to 3.33.4 contain an unauthenticated Remote Code Execution (RCE) flaw. Attackers can trigger Bash-based automations via a publ...

2026-04-04
Full analysis →
CVE-2026-33226
Analyzed
8.7
Budibase budibase

Budibase is a low code platform for creating internal tools, workflows, and admin panels

2026-03-21
Full analysis →
CVE-2026-31818
Analyzed
9.6
Budibase budibase

Budibase versions prior to 3.33.4 are vulnerable to Server-Side Request Forgery (SSRF). The SSRF protection is ineffective by default, allowing unauth...

2026-04-04
Full analysis →
CVE-2026-31816
Analyzed
9.1
Budibase budibase

A regex bypass in Budibase's middleware allows unauthenticated attackers to skip all authentication and authorization checks by appending a webhook pa...

2026-03-10
Full analysis →
CVE-2026-30240
Analyzed
9.6
Budibase budibase

A path traversal vulnerability in Budibase's PWA ZIP processing allows authenticated builders to exfiltrate sensitive server files, including environm...

2026-03-10
Full analysis →
CVE-2026-27702
Analyzed
9.9
Budibase budibase

Budibase Cloud suffers from an unsafe eval() vulnerability in its view filtering, allowing authenticated users to execute arbitrary JavaScript and acc...

2026-02-26
Full analysis →
CVE-2026-25737
Analyzed
8.9
Budibase budibase

Budibase is a low code platform for creating internal tools, workflows, and admin panels

2026-03-10
Full analysis →