VYPR
Vendor

Baserow

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2026-19754HigSep 2, 2026
    risk 0.56cvss epss

    Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treated as a SQL template and interpolated directly into a…

  • CVE-2021-22255HigAug 20, 2021
    risk 0.50cvss 7.7epss 0.01

    SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by inserting an internal address.

  • CVE-2026-81335HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch and record-name views in backend/src/baserow/contrib/builder/api/data_sources/views.py are declared with a permission class that admits any caller, so a…

  • CVE-2026-76837MedAug 24, 2026
    risk 0.35cvss 6.4epss 0.00

    Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/account/ stores the first_name value verbatim, and the mention renderer in web-frontend/modules/core/editor/mention.js builds its element with a template literal…

  • CVE-2026-18816MedAug 4, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to improper authentication. The attack may be…

  • CVE-2026-18817LowAug 4, 2026
    risk 0.14cvss 2.2epss 0.00

    A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. Performing a manipulation…