Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

nocodb — Vulnerabilities & Security Advisories 50

All 50 CVE vulnerabilities found in nocodb, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities affecting NocoDB, an open-source no-code platform that transforms any database into a smart spreadsheet interface, specifically categorized under general software weakness types and tagged for enterprise infrastructure monitoring. It aggregates a comprehensive list of Common Vulnerabilities and Exposures (CVEs) and security advisories related to the NocoDB application, covering reported issues from its initial public release through the most recent updates in the current year. Visitors to this resource can track the vendor’s specific security response timelines, gain a deeper understanding of the architectural weaknesses common in low-code development environments, and review the historical trend of defects patched in this specific product line over time. The data presented here is designed to help security professionals, compliance officers, and system administrators evaluate the risk posture of their NocoDB deployments by providing structured insights into past incidents and their resolutions. By analyzing these entries, users can identify patterns in how the development team addresses issues such as authentication flaws, data access controls, or cross-site scripting vulnerabilities. This historical context is essential for planning upgrade cycles, prioritizing remediation efforts, and ensuring that organizational databases protected by NocoDB remain secure against known exploitation techniques. The page serves as a neutral, factual record of the product’s security journey, facilitating informed decision-making without speculation or promotional bias.

Vendor: nocodb

CVE IDTitleCVSSSeverityPublished
CVE-2026-46547 NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL CWE-79 6.1 Medium2026-06-23
CVE-2026-46548 NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams) CWE-918 4.3 Medium2026-06-23
CVE-2026-46549 NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation CWE-863 2.0 Low2026-06-23
CVE-2026-46550 NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags CWE-614 5.4 Medium2026-06-23
CVE-2026-46552 NocoDB: Shared-base link access can invite arbitrary users as persistent base members CWE-285 5.8 Medium2026-06-23
CVE-2026-46553 NocoDB: Attachment Size Limit Bypass via Upload-by-URL CWE-770--2026-06-23
CVE-2026-47375 NocoDB: Postgres SQL Injection in Formula `ARRAYSORT` CWE-89 6.0 Medium2026-06-23
CVE-2026-47376 NocoDB: Reflected Cross-Site Scripting via Password Reset Token CWE-79--2026-06-23
CVE-2026-47377 NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin CWE-601--2026-06-23
CVE-2026-47378 NocoDB: Hidden Column Exposure in Public Shared View Endpoints CWE-639--2026-06-23
CVE-2026-47380 NocoDB: User Enumeration via Sign-In Timing CWE-208--2026-06-23
CVE-2026-46551 NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion CWE-770 6.5 Medium2026-06-23
CVE-2026-46554 NocoDB: Stale Auth Cache After API Token Deletion CWE-613--2026-06-23
CVE-2026-47382 NocoDB: Server-Side Request Forgery via Database Connection Host CWE-918--2026-06-23
CVE-2026-47279 NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints CWE-284--2026-06-23
CVE-2026-47379 NocoDB: Plaintext Password Comparison in Shared Views CWE-200--2026-06-23
CVE-2026-47381 NocoDB: Cross-Workspace Integration Use in Connection Test CWE-290--2026-06-23
CVE-2026-47383 NocoDB: Stored Cross-Site Scripting via Row Comments CWE-79--2026-06-23
CVE-2026-47384 NocoDB: SQL Injection via Column Title in Bulk GroupBy CWE-89--2026-06-23
CVE-2026-47385 NocoDB: Path Traversal via SQLite Source Filename CWE-22--2026-06-23
CVE-2026-47386 NocoDB: OAuth Authorization Code Race Condition CWE-362--2026-06-23
CVE-2026-47387 NocoDB: Stored Cross-Site Scripting via Form View Redirect URL CWE-79--2026-06-23
CVE-2026-47388 NocoDB: Missing Ownership Check in MCP Attachment Read CWE-639--2026-06-23
CVE-2026-53926 NocoDB: OAuth Tokens Persist Through Security Events CWE-613--2026-06-23
CVE-2026-53927 NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL CWE-918--2026-06-23
CVE-2026-53928 NocoDB: Refresh Tokens Persist Through Password Recovery CWE-613--2026-06-23
CVE-2026-53929 NocoDB: Stored Cross-Site Scripting via Secure Attachment CWE-79--2026-06-23
CVE-2026-53930 NocoDB: Server-Side Request Forgery via Base Migration URL CWE-918--2026-06-23
CVE-2026-53931 NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint CWE-441--2026-06-23
CVE-2026-28401 NocoDB: Stored Cross-Site Scripting via Rich Text Cells CWE-79 5.4AIMediumAI2026-03-02

All 50 known CVE vulnerabilities affecting nocodb with full Chinese analysis, references, and POCs where available.