Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint returned different responses for registered and unregistered emails, allowing user enumeration. This issue has been patched in version 0.301.3. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-28358.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-28359 | NocoDB: Stored Cross-Site Scripting via Rich Text Field | |
| CVE-2026-28401 | NocoDB: Stored Cross-Site Scripting via Rich Text Cells | |
| CVE-2026-28398 | NocoDB: Stored Cross-Site Scripting via Comments and Rich Text Cells | |
| CVE-2026-28361 | NocoDB: Missing Ownership Validation in MCP Token Operations | |
| CVE-2026-28399 | NocoDB: SQL Injection via DATEADD Formula | |
| CVE-2026-28357 | NocoDB: Stored Cross-Site Scripting via Formula Cell | |
| CVE-2026-28396 | NocoDB: Refresh Tokens Not Revoked on Password Reset | |
| CVE-2026-28360 | NocoDB: Plaintext Storage of Shared View Passwords | |
| CVE-2026-28397 | NocoDB: Stored Cross-Site Scripting via Comments |
No comments yet