VYPR

Nocodb

by Nocodb

npm: nocodb

Source repositories

CVEs (59)

  • CVE-2025-27506MedMar 6, 2025
    risk 0.28cvss 5.4epss 0.01

    NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId is vulnerable to Reflected Cross-Site-Scripting. The flaw…

  • CVE-2022-2079MedJun 14, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7+.

  • CVE-2026-47384MedJun 23, 2026
    risk 0.27cvss epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with column-create permission can inject SQL into the bulk groupBy endpoint by setting a column's title to a SQL fragment. The bulk groupBy path in group-by.ts builds three…

  • CVE-2026-28360MedMar 2, 2026
    risk 0.27cvss 5.3epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored in plaintext in the database and compared using direct string equality. This issue has been patched in version 0.301.3.

  • CVE-2026-28358MedMar 2, 2026
    risk 0.27cvss 5.3epss 0.01

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint returned different responses for registered and unregistered emails, allowing user enumeration. This issue has been patched in version 0.301.3.

  • CVE-2026-53930MedJun 23, 2026
    risk 0.26cvss epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the base-migration endpoint accepted a caller-supplied URL that the migration worker dereferenced without enforcing protocol or destination, allowing scheme abuse (file:, ftp:, etc.) and probing of…

  • CVE-2026-47377MedJun 23, 2026
    risk 0.26cvss epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin called window.location.replace() on a path extracted from the URL hash fragment after only checking hashPath.startsWith('/'). Protocol-relative URLs…

  • CVE-2026-47376MedJun 23, 2026
    risk 0.26cvss epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the password-reset page rendered the URL token directly into a JavaScript string literal in a server-rendered EJS template. EJS <%= %> HTML-entity-encodes a fixed set of characters but does not escape…

  • CVE-2026-24767MedJan 28, 2026
    risk 0.25cvss 4.9epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery (SSRF) vulnerability exists in the `uploadViaURL` functionality due to an unprotected `HEAD` request. While the subsequent file retrieval logic correctly…

  • CVE-2026-24766MedJan 28, 2026
    risk 0.25cvss 4.9epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-level-creator permissions can exploit prototype pollution in the `/api/v2/meta/connection/test` endpoint, causing all database write operations to fail…

  • CVE-2026-46548MedJun 23, 2026
    risk 0.21cvss 4.3epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the request-filtering-agent SSRF protection was non-functional in the four notification webhook plugins (Slack, Discord, Mattermost, Teams) because httpAgent / httpsAgent were passed as part of the…

  • CVE-2026-47388LowJun 23, 2026
    risk 0.15cvss epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a low-privilege MCP token holder with knowledge of an attachment path could read any file in shared storage, including attachments belonging to other bases and workspaces, because the MCP…

  • CVE-2026-46554LowJun 23, 2026
    risk 0.08cvss epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authenticate requests until their cache entry expired, because the auth cache was not invalidated by token value at deletion time. The API token deletion path removed…

  • CVE-2026-46553LowJun 23, 2026
    risk 0.07cvss epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the upload-by-URL path did not enforce NC_ATTACHMENT_FIELD_SIZE against either the remote file's advertised Content-Length or the decoded length of a data: URI, allowing an authenticated user to…

  • CVE-2026-46549LowJun 23, 2026
    risk 0.06cvss 2.0epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_scope and oauth_granted_resources to the request user, but the ACL middleware never consulted either. An OAuth token issued with a restricted scope (e.g.…

  • CVE-2022-2339HigJul 7, 2022
    risk 0.00cvss 7.5epss 0.02

    With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's contents. This attack can lead to leak of sensitive information.

  • CVE-2022-2022MedJun 7, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7.

  • CVE-2022-22121HigJan 10, 2022
    risk 0.00cvss 8.0epss 0.01

    In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint and exports the data as a…

  • CVE-2022-22120MedJan 10, 2022
    risk 0.00cvss 5.3epss 0.01

    In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered within the system. This allows…

Page 3 of 3