budibase vulnerabilities
CVEs whose affected-version data names the budibase package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
GHSA-qqf5-x7mj-v43pHigh· 8.4budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL
budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL
CVE-2026-48128MediumBudibase: SSRF via User-Controlled queryId in Automation Execute Query Step
Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step
CVE-2026-31818Critical· 9.6Budibase is an open-source low-code platform
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered…
CVE-2026-25044High· 8.8Budibase is an open-source low-code platform
Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper sanitization or validation. User input is processed through processStringSync w…
CVE-2026-25043Medium· 5.3Budibase is an open-source low-code platform
Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functionality due to the absence of rate limiting, CAPTCHA, or abuse prevention mechanisms on the …