Budibase
23 known vulnerabilities
Top Products
Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypas
Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/ro
Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly acce
Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase ap
Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a worksp
Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoin
Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a publi
Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT sess
Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expr
Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Co
Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerabilit
Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided c
Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibas
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and pr
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Bud
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbi
Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the Po
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an un
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and includin
Frequently Asked Questions
How many CVEs affect Budibase?
Budibase has 23 CVE records in our database, including 9 critical and 13 high severity vulnerabilities.
What are the most severe Budibase vulnerabilities?
Budibase has 9 critical severity (CVSS 9.0+) and 13 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Budibase vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Budibase products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Budibase Vulnerabilities
CyberStrike scans your infrastructure for Budibase vulnerabilities and provides real-time remediation guidance.
Get Started