VYPR

Vendor CVEs

Nocodb

All CVEs

59 total · sorted by risk
  • CVE-2026-47387HigJun 23, 2026
    risk 0.55cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared form-view submit handler (packages/nc-gui/composables/useSharedFormViewStore.ts) in NocoDB writes the form's redirect_url to window.location.href after a same-host check that does not…

  • CVE-2026-24769CriJan 28, 2026
    risk 0.52cvss 9.0epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS) vulnerability exists in NocoDB’s attachment handling mechanism. Authenticated users can upload malicious SVG files containing embedded JavaScript, which are…

  • CVE-2026-28399HigMar 2, 2026
    risk 0.50cvss 8.8epss 0.01

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Creator role can inject arbitrary SQL via the DATEADD formula's unit parameter. This issue has been patched in version 0.301.3.

  • CVE-2022-2064HigJun 13, 2022
    risk 0.50cvss 8.8epss 0.01

    Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.

  • CVE-2022-2063HigJun 13, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.

  • CVE-2023-35843HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.09

    NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files…

  • CVE-2026-47383HigJun 23, 2026
    risk 0.48cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated commenter could store HTML in row comments that executed as script when other users hovered over the comment in the expanded form view. The comment write paths persisted the raw…

  • CVE-2026-53931MedJun 23, 2026
    risk 0.45cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-import endpoint axiosRequestMake could be used as a generic HTTP proxy. Before the fix it was reachable unauthenticated, and its URL-extension allowlist was a regex tested against the…

  • CVE-2023-50718MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on MySQL DB using unescaped `table_name`. This vulnerability may result in leakage of sensitive data in the…

  • CVE-2023-43794MedOct 17, 2023
    risk 0.42cvss 6.5epss 0.01

    Nocodb is an open source Airtable alternative. Affected versions of nocodb contain a SQL injection vulnerability, that allows an authenticated attacker with creator access to query the underlying database. By supplying a specially crafted payload to the given an attacker can…

  • CVE-2022-2062HigJun 13, 2022
    risk 0.42cvss 7.5epss 0.01

    Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.

  • CVE-2022-3423HigOct 7, 2022
    risk 0.41cvss 7.3epss 0.02

    Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0.

  • CVE-2023-49781HigMay 14, 2024
    risk 0.40cvss 7.3epss 0.01

    NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a stored cross-site scripting vulnerability exists within the Formula virtual cell comments functionality. The nc-gui/components/virtual-cell/Formula.vue displays a v-html tag with the value of "urls"…

  • CVE-2026-47375MedJun 23, 2026
    risk 0.39cvss 6.0epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, an authenticated user with columnAdd permission on a Postgres-backed base can inject arbitrary SQL into the formula engine via the optional direction argument of ARRAYSORT(...). The value is…

  • CVE-2026-47381MedJun 23, 2026
    risk 0.38cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a user in one workspace could exercise another workspace's integration through the testConnection endpoint by supplying its ID, because the integration was fetched in a bypass scope and the caller's…

  • CVE-2026-47379MedJun 23, 2026
    risk 0.38cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared-view password check fell back to strict-equality (===) comparison for legacy plaintext passwords, leaking the password's length and per-character prefix through response timing. This…

  • CVE-2026-47378MedJun 23, 2026
    risk 0.38cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, Public shared-view endpoints exposed values from columns that the view owner had hidden, via three independent paths: groupBy returned raw values for any column named in the request, filter and sort…

  • CVE-2026-47279MedJun 23, 2026
    risk 0.38cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without verifying that the column was visible in the shared view, so anyone holding a share UUID could read links from…

  • CVE-2023-50717MedMay 14, 2024
    risk 0.37cvss 5.7epss 0.01

    NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed leading stored cross-site…

  • CVE-2026-46551MedJun 23, 2026
    risk 0.35cvss 6.5epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, the uploadViaURL path in the v1/v2 attachment API did not enforce NC_ATTACHMENT_FIELD_SIZE against the remote content-length or against the response stream. An authenticated user (Editor+) could…

  • CVE-2026-28396MedMar 2, 2026
    risk 0.35cvss 6.5epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset flow did not revoke existing refresh tokens, allowing an attacker with a previously stolen refresh token to continue minting valid JWTs after the victim resets their password.…

  • CVE-2023-5104MedSep 21, 2023
    risk 0.35cvss 6.5epss 0.01

    Improper Input Validation in GitHub repository nocodb/nocodb prior to 0.96.0.

  • CVE-2026-53928MedJun 23, 2026
    risk 0.34cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a stolen refresh token survived a password-forgot flow and could be used to mint fresh JWTs even after the user reset their password. passwordChange and passwordReset deleted the user's refresh…

  • CVE-2026-53926MedJun 23, 2026
    risk 0.34cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, revokeAllOAuthTokensByUser in the users service is an empty stub being called from passwordChange, passwordForgot, and passwordReset. OAuth access and refresh tokens were not revoked when the user…

  • CVE-2026-47386MedJun 23, 2026
    risk 0.34cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, two concurrent token-exchange requests using the same OAuth authorization code could each mint a distinct valid (access_token, refresh_token) pair, breaking the single-use guarantee that PKCE relies…

  • CVE-2026-47385MedJun 23, 2026
    risk 0.34cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with base-create permission can attach a SQLite source pointing at an arbitrary file on the NocoDB host, including NocoDB's own internal databases. The SQLite client and the…

  • CVE-2026-47382MedJun 23, 2026
    risk 0.34cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the connection-test endpoint opened a raw TCP socket to the user-supplied database host without resolving and range-checking the destination, so private and link-local addresses (including IPv4-mapped…

  • CVE-2026-47380MedJun 23, 2026
    risk 0.34cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, sign-in response timing differed between known and unknown email addresses because the unknown-user branch returned without performing a password hash comparison. This vulnerability is fixed in…

  • CVE-2026-28361MedMar 2, 2026
    risk 0.34cvss 6.3epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not validate token ownership, allowing a Creator within the same base to read, regenerate, or delete another user's MCP tokens if the token ID was known. This issue has…

  • CVE-2026-53929MedJun 23, 2026
    risk 0.33cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, with NC_SECURE_ATTACHMENTS=true, an authenticated uploader could deliver .html or .svg attachments that the browser rendered inline from the NocoDB origin instead of forcing a download. The signed…

  • CVE-2026-53927MedJun 23, 2026
    risk 0.33cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-fetch endpoint (axiosRequestMake) accepted URLs whose path contained a permitted extension anywhere in the string, and applied a hand-rolled regex blocklist that omitted 127.0.0.0/8…

  • CVE-2026-46547MedJun 23, 2026
    risk 0.33cvss 6.1epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, a reflected XSS vulnerability exists in the Page Leaving Warning page. The ncRedirectUrl and ncBackUrl query parameters are used in window.location.href and tag bindings without validation,…

  • CVE-2026-24768MedJan 28, 2026
    risk 0.33cvss 6.1epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an unvalidated redirect (open redirect) vulnerability exists in NocoDB’s login flow due to missing validation of the `continueAfterSignIn` parameter. During authentication, NocoDB processes a…

  • CVE-2026-46552MedJun 23, 2026
    risk 0.31cvss 5.8epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, shared-base sessions were granted the same base-member capabilities as authenticated viewers. Using only the shared-base UUID (xc-shared-base-id), an attacker could enumerate base members and invite…

  • CVE-2026-46550MedJun 23, 2026
    risk 0.28cvss 5.4epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the refresh-token cookie was set with httpOnly: true but missing both the secure flag and the sameSite attribute. Over plain HTTP the cookie could be intercepted on the network; without sameSite,…

  • CVE-2026-28401MedMar 2, 2026
    risk 0.28cvss 5.4epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, rich text cell content rendered via v-html without sanitization enables stored XSS. This issue has been patched in version 0.301.3.

  • CVE-2026-28398MedMar 2, 2026
    risk 0.28cvss 5.4epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, user-controlled content in comments and rich text cells was rendered via v-html without sanitization, enabling stored XSS. This issue has been patched in version 0.301.3.

  • CVE-2026-28397MedMar 2, 2026
    risk 0.28cvss 5.4epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, comments rendered via v-html without sanitization enable stored XSS. This issue has been patched in version 0.301.3.

  • CVE-2026-28359MedMar 2, 2026
    risk 0.28cvss 5.4epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Editor role can inject arbitrary HTML into Rich Text cells by bypassing the TipTap editor and sending raw HTML via the API. This issue has been patched in version…

  • CVE-2026-28357MedMar 2, 2026
    risk 0.28cvss 5.4epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, a stored XSS vulnerability exists in the Formula virtual cell. Formula results containing URI::() patterns are rendered via v-html without sanitization, allowing injected HTML to execute. This…

  • CVE-2025-27506MedMar 6, 2025
    risk 0.28cvss 5.4epss 0.01

    NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId is vulnerable to Reflected Cross-Site-Scripting. The flaw…

  • CVE-2022-2079MedJun 14, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7+.

  • CVE-2026-47384MedJun 23, 2026
    risk 0.27cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with column-create permission can inject SQL into the bulk groupBy endpoint by setting a column's title to a SQL fragment. The bulk groupBy path in group-by.ts builds three…

  • CVE-2026-28360MedMar 2, 2026
    risk 0.27cvss 5.3epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored in plaintext in the database and compared using direct string equality. This issue has been patched in version 0.301.3.

  • CVE-2026-28358MedMar 2, 2026
    risk 0.27cvss 5.3epss 0.01

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint returned different responses for registered and unregistered emails, allowing user enumeration. This issue has been patched in version 0.301.3.

  • CVE-2026-53930MedJun 23, 2026
    risk 0.26cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the base-migration endpoint accepted a caller-supplied URL that the migration worker dereferenced without enforcing protocol or destination, allowing scheme abuse (file:, ftp:, etc.) and probing of…

  • CVE-2026-47377MedJun 23, 2026
    risk 0.26cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin called window.location.replace() on a path extracted from the URL hash fragment after only checking hashPath.startsWith('/'). Protocol-relative URLs…

  • CVE-2026-47376MedJun 23, 2026
    risk 0.26cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the password-reset page rendered the URL token directly into a JavaScript string literal in a server-rendered EJS template. EJS <%= %> HTML-entity-encodes a fixed set of characters but does not escape…

  • CVE-2026-24767MedJan 28, 2026
    risk 0.25cvss 4.9epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery (SSRF) vulnerability exists in the `uploadViaURL` functionality due to an unprotected `HEAD` request. While the subsequent file retrieval logic correctly…

  • CVE-2026-24766MedJan 28, 2026
    risk 0.25cvss 4.9epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, an authenticated user with org-level-creator permissions can exploit prototype pollution in the `/api/v2/meta/connection/test` endpoint, causing all database write operations to fail…

Page 1 of 2