VulnSea

apitable has 4 CVEs on record. 4 were published in the last 90 days. The median CVSS is 6.4 (medium). The most common weakness class is CWE-306 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.4
Publish → KEV
Last 90 days
4 prev 0

Weakness classes

Products

  • apitable 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

apitable vulnerabilities

CVEs affecting apitable, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-86120Medium· 4.3
2w ago

APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions

APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can …

Sunlitapitable · apitableEPSS 0.21%via NVD
CVE-2026-84485High· 7.5
3w ago

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endp…

Twilightapitable · apitableEPSS 0.35%via NVD
CVE-2026-80208High· 8.2
4w ago

APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false

APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is val…

Twilightapitable · apitableEPSS 0.31%via NVD
CVE-2026-80207Medium· 5.3PoC
4w ago

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gatewa…

Twilightapitable · apitableEPSS 0.29%via NVD
apitable vulnerabilities (CVEs) · VulnSea