nocodb
50 known vulnerabilities · 0 critical · 4 high
NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells
NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS
NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality
NocoDB Vulnerable to Stored Cross-site Scripting via Rich Text Field
NocoDB Vulnerable to Stored Cross-Site Scripting via Rich Text Cells
NocoDB has Unvalidated Redirect in Login Flow via continueAfterSignIn Parameter
NocoDB: Hidden Column Exposure in Public Shared View Endpoints
NocoDB: OAuth Authorization Code Race Condition
NocoDB: Reflected Cross-Site Scripting via Password Reset Token
NocoDB: Cross-Workspace Integration Use in Connection Test
NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints
NocoDB: Postgres SQL Injection in Formula `ARRAYSORT`
NocoDB: Stored Cross-Site Scripting via Row Comments
NocoDB: User Enumeration via Sign-In Timing
NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin
NocoDB: Plaintext Password Comparison in Shared Views
NocoDB: Path Traversal via SQLite Source Filename
NocoDB: Server-Side Request Forgery via Database Connection Host
NocoDB Vulnerable to User Enumeration via Password Reset Endpoint
NocoDB: SQL Injection via Column Title in Bulk GroupBy
NocoDB: OAuth Tokens Persist Through Security Events
NocoDB: Stored Cross-Site Scripting via Form View Redirect URL
NocoDB: Missing Ownership Check in MCP Attachment Read
NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
NocoDB: Attachment Size Limit Bypass via Upload-by-URL
NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
NocoDB: Stored Cross-Site Scripting via Secure Attachment
NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL
NocoDB: Server-Side Request Forgery via Base Migration URL
NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
NocoDB: Stale Auth Cache After API Token Deletion
NocoDB: Refresh Tokens Persist Through Password Recovery