OsVault/npm/nocodb
npm

nocodb

21 known vulnerabilities · 0 critical · 4 high

CVE-2022-2064HIGH

Insufficient Session Expiration in NocoDB

Published Jun 14, 2022
CVE-2026-24768

NocoDB has Unvalidated Redirect in Login Flow via continueAfterSignIn Parameter

Published Jan 28, 2026
CVE-2023-43794MEDIUM

nocodb SQL Injection vulnerability

Published Oct 17, 2023
CVE-2022-2062HIGH

NocoDB information disclosure vulnerability

Published Jun 14, 2022
CVE-2026-28398

NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells

Published Mar 3, 2026
CVE-2026-28357

NocoDB has Stored Cross-site Scripting via Formula Cell

Published Mar 2, 2026
CVE-2026-28399

NocoDB Vulnerable to SQL Injection via DATEADD Formula

Published Mar 3, 2026
CVE-2026-24766

NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS

Published Jan 28, 2026
CVE-2022-2079MEDIUM

Cross-site Scripting in NocoDB

Published Jun 15, 2022
CVE-2026-28361

NocoDB Missing Ownership Validation in MCP Token Operations

Published Mar 2, 2026
CVE-2026-24767

NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality

Published Jan 28, 2026
CVE-2023-5104MEDIUM

Improper Input Validation in nocodb

Published Sep 21, 2023
CVE-2026-28358

NocoDB Vulnerable to User Enumeration via Password Reset Endpoint

Published Mar 2, 2026
CVE-2022-2063HIGH

Improper Privilege Management in NocoDB

Published Jun 14, 2022
CVE-2022-3423HIGH

NocoDB vulnerable to Denial of Service

Published Oct 7, 2022
CVE-2026-28360

NocoDB has Plaintext Storage of Shared View Passwords

Published Mar 2, 2026
CVE-2026-24769

NocoDB Vulnerable to Stored Cross-Site Scripting via SVG upload

Published Jan 28, 2026
CVE-2026-28359

NocoDB Vulnerable to Stored Cross-site Scripting via Rich Text Field

Published Mar 2, 2026
CVE-2026-28401

NocoDB Vulnerable to Stored Cross-Site Scripting via Rich Text Cells

Published Mar 3, 2026
CVE-2026-28397

NocoDB Vulnerable to Stored Cross-site Scripting via Comments

Published Mar 3, 2026
CVE-2026-28396

NocoDB's Refresh Tokens Not Revoked on Password Reset

Published Mar 2, 2026
Check your entire dependency tree at onceRun dependency scan →