Home/Product/budibase
Product

budibase

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-41428
< 3.35.4
Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to
9.1CRITICAL
CVE-2026-35218
< 3.32.5
Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity names (ta
8.7HIGH
CVE-2026-35216
< 3.33.4
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Executi
9.0CRITICAL
CVE-2026-35214
< 3.33.4
Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin/upload) p
8.7HIGH
CVE-2026-31818
< 3.33.4
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists i
9.6CRITICAL
CVE-2026-25044
< 3.33.4
Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands us
8.8HIGH
CVE-2026-25043
< 3.23.25
Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s pass
5.3MEDIUM
CVE-2026-33226
<= 3.30.6
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the R
8.7HIGH
CVE-2026-31816
<= 3.31.4
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase serv
9.1CRITICAL
CVE-2026-30240
<= 3.31.5
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal
9.6CRITICAL
CVE-2026-25737
<= 3.24.0
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file
8.9HIGH
CVE-2026-25045
<= 3.32.3
Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of Vertical
8.8HIGH
CVE-2026-25041
<= 3.23.22
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the PostgreSQL i
7.2HIGH
CVE-2026-27702
< 3.30.4
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval
9.9CRITICAL
CVE-2026-25040
<= 3.26.3
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and including 3.26.3,
8.8HIGH
CVE-2023-29010
< 2.4.3
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023)
6.5MEDIUM
CVE-2022-3225
< 1.3.20
Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20.
8.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin