Insufficient Session Expiration in NocoDB
Published Jun 14, 2022
NocoDB has Unvalidated Redirect in Login Flow via continueAfterSignIn Parameter
Published Jan 28, 2026
nocodb SQL Injection vulnerability
Published Oct 17, 2023
NocoDB information disclosure vulnerability
Published Jun 14, 2022
NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells
Published Mar 3, 2026
NocoDB has Stored Cross-site Scripting via Formula Cell
Published Mar 2, 2026
NocoDB Vulnerable to SQL Injection via DATEADD Formula
Published Mar 3, 2026
NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS
Published Jan 28, 2026
Cross-site Scripting in NocoDB
Published Jun 15, 2022
NocoDB Missing Ownership Validation in MCP Token Operations
Published Mar 2, 2026
NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality
Published Jan 28, 2026
Improper Input Validation in nocodb
Published Sep 21, 2023
NocoDB Vulnerable to User Enumeration via Password Reset Endpoint
Published Mar 2, 2026
Improper Privilege Management in NocoDB
Published Jun 14, 2022
NocoDB vulnerable to Denial of Service
Published Oct 7, 2022
NocoDB has Plaintext Storage of Shared View Passwords
Published Mar 2, 2026
NocoDB Vulnerable to Stored Cross-Site Scripting via SVG upload
Published Jan 28, 2026
NocoDB Vulnerable to Stored Cross-site Scripting via Rich Text Field
Published Mar 2, 2026
NocoDB Vulnerable to Stored Cross-Site Scripting via Rich Text Cells
Published Mar 3, 2026
NocoDB Vulnerable to Stored Cross-site Scripting via Comments
Published Mar 3, 2026
NocoDB's Refresh Tokens Not Revoked on Password Reset
Published Mar 2, 2026