VYPR

Vendor CVEs

Nocodb

All CVEs

59 total · sorted by risk
  • CVE-2026-46548MedJun 23, 2026
    risk 0.21cvss 4.3epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the request-filtering-agent SSRF protection was non-functional in the four notification webhook plugins (Slack, Discord, Mattermost, Teams) because httpAgent / httpsAgent were passed as part of the…

  • CVE-2026-47388LowJun 23, 2026
    risk 0.15cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a low-privilege MCP token holder with knowledge of an attachment path could read any file in shared storage, including attachments belonging to other bases and workspaces, because the MCP…

  • CVE-2026-46554LowJun 23, 2026
    risk 0.08cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authenticate requests until their cache entry expired, because the auth cache was not invalidated by token value at deletion time. The API token deletion path removed…

  • CVE-2026-46553LowJun 23, 2026
    risk 0.07cvss —epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the upload-by-URL path did not enforce NC_ATTACHMENT_FIELD_SIZE against either the remote file's advertised Content-Length or the decoded length of a data: URI, allowing an authenticated user to…

  • CVE-2026-46549LowJun 23, 2026
    risk 0.06cvss 2.0epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_scope and oauth_granted_resources to the request user, but the ACL middleware never consulted either. An OAuth token issued with a restricted scope (e.g.…

  • CVE-2022-2339HigJul 7, 2022
    risk 0.00cvss 7.5epss 0.02

    With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's contents. This attack can lead to leak of sensitive information.

  • CVE-2022-2022MedJun 7, 2022
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7.

  • CVE-2022-22121HigJan 10, 2022
    risk 0.00cvss 8.0epss 0.01

    In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint and exports the data as a…

  • CVE-2022-22120MedJan 10, 2022
    risk 0.00cvss 5.3epss 0.01

    In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered within the system. This allows…

Page 2 of 2