Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.1 CVE-2026-47377

NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin_CVE-2026-47377

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin called window.location.replace()...

nocodb nocodb < 2026.04.1 CVE
MEDIUM 5.1 CVE-2026-47376

NocoDB: Reflected Cross-Site Scripting via Password Reset Token_CVE-2026-47376

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the password-reset page rendered the URL token directly into a JavaS...

nocodb nocodb < 2026.04.1 CVE
MEDIUM 6 CVE-2026-47375

NocoDB: Postgres SQL Injection in Formula `ARRAYSORT`_CVE-2026-47375

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, an authenticated user with columnAdd permission on a Postgres-backed...

nocodb nocodb < 2026.04.1 CVE
MEDIUM 6.9 CVE-2026-47279

NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints_CVE-2026-47279

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied...

nocodb nocodb < 2026.05.1 CVE
MEDIUM 5.8 CVE-2026-46552

NocoDB: Shared-base link access can invite arbitrary users as persistent base members_CVE-2026-46552

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, shared-base sessions were granted the same base-member capabilities ...

nocodb nocodb < 2026.04.1 CVE
MEDIUM 6.5 CVE-2026-46551

NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion_CVE-2026-46551

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, the uploadViaURL path in the v1/v2 attachment API did not enforce NC...

nocodb nocodb < 2026.04.4 CVE
MEDIUM 5.4 CVE-2026-46550

NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags_CVE-2026-46550

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the refresh-token cookie was set with httpOnly: true but missing bot...

nocodb nocodb < 2026.04.1 CVE
MEDIUM 4.3 CVE-2026-46548

NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)_CVE-2026-46548

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the request-filtering-agent SSRF protection was non-functional in th...

nocodb nocodb < 2026.04.1 CVE
MEDIUM 6.1 CVE-2026-46547

NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL_CVE-2026-46547

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, a reflected XSS vulnerability exists in the Page Leaving Warning pag...

nocodb nocodb < 2026.04.1 CVE
MEDIUM 6.5 CVE-2026-54518

jackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databind_CVE-2026-54518

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3....

FasterXML jackson-databind >= 2.21.0, < 2.21.4 CVE