Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | https://github.com/vulhub/vulhub/blob/master/budibase/CVE-2026-31816/README.md | POC Details | |
| 2 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Budibase%20Webhook%20%E6%9F%A5%E8%AF%A2%E5%8F%82%E6%95%B0%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%20CVE-2026-31816.md | POC Details |
| 3 | Budibase <= 3.31.4 contains an authentication bypass caused by unanchored regex in authorized() middleware matching webhook path patterns in query strings, letting unauthenticated remote attackers access any server-side API endpoint, exploit requires crafted request with webhook pattern in URL. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-31816.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-30240 | 9.6 CRITICAL | Budibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All |
| CVE-2026-25737 | 8.9 HIGH | Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored |
| CVE-2026-25045 | Budibase Critical Privilege Escalation & IDOR via Missing RBAC on User Role Management (Cr | |
| CVE-2026-25041 | Budibase has a Command Injection in PostgreSQL Dump Command |
No comments yet