Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

nocodb — Vulnerabilities & Security Advisories 58

Browse all 58 CVE security advisories affecting nocodb. AI-powered Chinese analysis, POCs, and references for each vulnerability.

NocoDB is an open-source platform that transforms relational databases into intuitive spreadsheet interfaces, enabling rapid application development without extensive coding. Despite its utility, the software has accumulated twenty-nine recorded Common Vulnerabilities and Exposures (CVEs), indicating significant historical security challenges. Analysis of these flaws reveals a prevalence of critical vulnerability classes, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Privilege Escalation. These issues often stem from insufficient input validation and improper access control mechanisms within the application’s API layers. While no single catastrophic data breach has been widely publicized as a defining incident, the sheer volume of disclosed CVEs suggests systemic weaknesses in the codebase’s security architecture. Users are advised to prioritize strict patch management and rigorous environment hardening to mitigate risks associated with these known exploitable conditions.

Top products by nocodb: nocodb nocodb/nocodb
CVE IDTitleCVSSSeverityPublished
CVE-2026-46547 NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL — nocodbCWE-79 6.1 Medium2026-06-23
CVE-2026-46548 NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams) — nocodbCWE-918 4.3 Medium2026-06-23
CVE-2026-46549 NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation — nocodbCWE-863 2.0 Low2026-06-23
CVE-2026-46550 NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags — nocodbCWE-614 5.4 Medium2026-06-23
CVE-2026-46552 NocoDB: Shared-base link access can invite arbitrary users as persistent base members — nocodbCWE-285 5.8 Medium2026-06-23
CVE-2026-46553 NocoDB: Attachment Size Limit Bypass via Upload-by-URL — nocodbCWE-770--2026-06-23
CVE-2026-47375 NocoDB: Postgres SQL Injection in Formula `ARRAYSORT` — nocodbCWE-89 6.0 Medium2026-06-23
CVE-2026-47376 NocoDB: Reflected Cross-Site Scripting via Password Reset Token — nocodbCWE-79--2026-06-23
CVE-2026-47377 NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin — nocodbCWE-601--2026-06-23
CVE-2026-47378 NocoDB: Hidden Column Exposure in Public Shared View Endpoints — nocodbCWE-639--2026-06-23
CVE-2026-47380 NocoDB: User Enumeration via Sign-In Timing — nocodbCWE-208--2026-06-23
CVE-2026-46551 NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion — nocodbCWE-770 6.5 Medium2026-06-23
CVE-2026-46554 NocoDB: Stale Auth Cache After API Token Deletion — nocodbCWE-613--2026-06-23
CVE-2026-47382 NocoDB: Server-Side Request Forgery via Database Connection Host — nocodbCWE-918--2026-06-23
CVE-2026-47279 NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints — nocodbCWE-284--2026-06-23
CVE-2026-47379 NocoDB: Plaintext Password Comparison in Shared Views — nocodbCWE-200--2026-06-23
CVE-2026-47381 NocoDB: Cross-Workspace Integration Use in Connection Test — nocodbCWE-290--2026-06-23
CVE-2026-47383 NocoDB: Stored Cross-Site Scripting via Row Comments — nocodbCWE-79--2026-06-23
CVE-2026-47384 NocoDB: SQL Injection via Column Title in Bulk GroupBy — nocodbCWE-89--2026-06-23
CVE-2026-47385 NocoDB: Path Traversal via SQLite Source Filename — nocodbCWE-22--2026-06-23
CVE-2026-47386 NocoDB: OAuth Authorization Code Race Condition — nocodbCWE-362--2026-06-23
CVE-2026-47387 NocoDB: Stored Cross-Site Scripting via Form View Redirect URL — nocodbCWE-79--2026-06-23
CVE-2026-47388 NocoDB: Missing Ownership Check in MCP Attachment Read — nocodbCWE-639--2026-06-23
CVE-2026-53926 NocoDB: OAuth Tokens Persist Through Security Events — nocodbCWE-613--2026-06-23
CVE-2026-53927 NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL — nocodbCWE-918--2026-06-23
CVE-2026-53928 NocoDB: Refresh Tokens Persist Through Password Recovery — nocodbCWE-613--2026-06-23
CVE-2026-53929 NocoDB: Stored Cross-Site Scripting via Secure Attachment — nocodbCWE-79--2026-06-23
CVE-2026-53930 NocoDB: Server-Side Request Forgery via Base Migration URL — nocodbCWE-918--2026-06-23
CVE-2026-53931 NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint — nocodbCWE-441--2026-06-23
CVE-2026-28401 NocoDB: Stored Cross-Site Scripting via Rich Text Cells — nocodbCWE-79 5.4AIMediumAI2026-03-02

This page lists every published CVE security advisory associated with nocodb. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.