Vendor CVEs
ToolJet
All CVEs
22 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-82874 | Cri | 0.64 | 9.9 | 0.00 | Aug 31, 2026 | ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract… | ||
| CVE-2026-82870 | Cri | 0.62 | 9.6 | 0.00 | Aug 31, 2026 | ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing organization-resolving guards to permanently… | ||
| CVE-2026-82872 | Cri | 0.52 | 9.1 | 0.01 | Aug 31, 2026 | ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId… | ||
| CVE-2026-82871 | Hig | 0.50 | 7.7 | 0.00 | Aug 31, 2026 | ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL parameters to list tables, retrieve… | ||
| CVE-2026-82869 | Hig | 0.50 | 7.7 | 0.00 | Aug 31, 2026 | ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or workspace membership validation. Attackers can read arbitrary ToolJet Database tables… | ||
| CVE-2022-27978 | Hig | 0.49 | 7.5 | 0.01 | Apr 26, 2023 | Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request. | ||
| CVE-2026-82875 | Med | 0.36 | 5.5 | 0.00 | Aug 31, 2026 | ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can enumerate, create, rename, and delete… | ||
| CVE-2022-27979 | Med | 0.35 | 5.4 | 0.00 | Apr 26, 2023 | A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component. | ||
| CVE-2022-4111 | Med | 0.35 | 6.5 | 0.01 | Nov 22, 2022 | Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures over 2MB. | ||
| CVE-2026-82873 | Med | 0.33 | 5.0 | 0.00 | Aug 31, 2026 | ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and export app definitions across granular permission… | ||
| CVE-2026-73068 | Med | 0.31 | 5.9 | 0.00 | Aug 11, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations against the :organizationId URL… | ||
| CVE-2026-54344 | Med | 0.31 | 4.7 | 0.00 | Jul 8, 2026 | ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview deployment workflow interpolates github.event.comment.body directly into a bash conditional in a run step, allowing any GitHub user who can comment on an open… | ||
| CVE-2026-55413 | Cri | 0.00 | — | 0.00 | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, any authenticated user with builder role (free tier) can overwrite a globally-shared marketplace plugin with arbitrary… | ||
| CVE-2026-55412 | Hig | 0.00 | 8.3 | 0.00 | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, there's an SSRF in the RestAPI data source component. The RestAPI data source executes HTTP requests server-side, and its… | ||
| CVE-2026-55411 | Med | 0.00 | 6.8 | 0.00 | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint POST /api/data-sources/decrypt returns the decrypted plaintext for any credential whose… | ||
| CVE-2022-3422 | Hig | 0.00 | 7.5 | 0.01 | Oct 7, 2022 | Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass | ||
| CVE-2022-3348 | Med | 0.00 | 4.9 | 0.01 | Sep 28, 2022 | Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a little bit more specific, because it is needed to be an editor in the same app as the victim. | ||
| CVE-2022-3019 | Hig | 0.00 | 8.8 | 0.01 | Aug 29, 2022 | The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one). | ||
| CVE-2022-2631 | Hig | 0.00 | 8.8 | 0.01 | Aug 2, 2022 | Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0. | ||
| CVE-2022-2037 | Hig | 0.00 | 8.0 | 0.01 | Jun 9, 2022 | Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0. | ||
| CVE-2022-23068 | Med | 0.00 | 5.4 | 0.01 | May 18, 2022 | ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail. | ||
| CVE-2022-23067 | Hig | 0.00 | 8.8 | 0.01 | May 18, 2022 | ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer… |
- risk 0.64cvss 9.9epss 0.00
ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract…
- risk 0.62cvss 9.6epss 0.00
ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing organization-resolving guards to permanently…
- risk 0.52cvss 9.1epss 0.01
ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId…
- risk 0.50cvss 7.7epss 0.00
ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL parameters to list tables, retrieve…
- risk 0.50cvss 7.7epss 0.00
ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or workspace membership validation. Attackers can read arbitrary ToolJet Database tables…
- risk 0.49cvss 7.5epss 0.01
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.
- risk 0.36cvss 5.5epss 0.00
ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can enumerate, create, rename, and delete…
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component.
- risk 0.35cvss 6.5epss 0.01
Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures over 2MB.
- risk 0.33cvss 5.0epss 0.00
ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and export app definitions across granular permission…
- risk 0.31cvss 5.9epss 0.00
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations against the :organizationId URL…
- risk 0.31cvss 4.7epss 0.00
ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview deployment workflow interpolates github.event.comment.body directly into a bash conditional in a run step, allowing any GitHub user who can comment on an open…
- risk 0.00cvss —epss 0.00
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, any authenticated user with builder role (free tier) can overwrite a globally-shared marketplace plugin with arbitrary…
- risk 0.00cvss 8.3epss 0.00
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, there's an SSRF in the RestAPI data source component. The RestAPI data source executes HTTP requests server-side, and its…
- risk 0.00cvss 6.8epss 0.00
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint POST /api/data-sources/decrypt returns the decrypted plaintext for any credential whose…
- risk 0.00cvss 7.5epss 0.01
Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass
- risk 0.00cvss 4.9epss 0.01
Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a little bit more specific, because it is needed to be an editor in the same app as the victim.
- risk 0.00cvss 8.8epss 0.01
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).
- risk 0.00cvss 8.8epss 0.01
Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.
- risk 0.00cvss 8.0epss 0.01
Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.
- risk 0.00cvss 5.4epss 0.01
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.
- risk 0.00cvss 8.8epss 0.01
ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer…