Vulnerabilities
CVE-2026-53926
NocoDB: OAuth Tokens Persist Through Security Events
CVE-2026-47386
NocoDB: OAuth Authorization Code Race Condition
CVE-2026-47388
NocoDB: Missing Ownership Check in MCP Attachment Read
CVE-2026-47385
NocoDB: Path Traversal via SQLite Source Filename
CVE-2026-47387
NocoDB: Stored Cross-Site Scripting via Form View Redirect URL
CVE-2026-47384
NocoDB: SQL Injection via Column Title in Bulk GroupBy
CVE-2026-47383
NocoDB: Stored Cross-Site Scripting via Row Comments
CVE-2026-47382
NocoDB: Server-Side Request Forgery via Database Connection Host
CVE-2026-47381
NocoDB: Cross-Workspace Integration Use in Connection Test
CVE-2026-47378
NocoDB: Hidden Column Exposure in Public Shared View Endpoints
CVE-2026-47375
NocoDB: Postgres SQL Injection in Formula `ARRAYSORT`
CVE-2026-47380
NocoDB: User Enumeration via Sign-In Timing
CVE-2026-47376
NocoDB: Reflected Cross-Site Scripting via Password Reset Token
CVE-2026-47379
NocoDB: Plaintext Password Comparison in Shared Views
CVE-2026-47377
NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin
CVE-2026-47279
NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints
CVE-2026-46547
NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
CVE-2026-46550
NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags
CVE-2026-46548
NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
CVE-2026-46554
NocoDB: Stale Auth Cache After API Token Deletion
CVE-2026-46553
NocoDB: Attachment Size Limit Bypass via Upload-by-URL
CVE-2026-46551
NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
CVE-2026-46552
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
CVE-2026-46549
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
CVE-2026-28357
NocoDB has Stored Cross-site Scripting via Formula Cell
CVE-2026-28396
NocoDB's Refresh Tokens Not Revoked on Password Reset
CVE-2026-28361
NocoDB Missing Ownership Validation in MCP Token Operations
CVE-2026-28397
NocoDB Vulnerable to Stored Cross-site Scripting via Comments
CVE-2026-28359
NocoDB Vulnerable to Stored Cross-site Scripting via Rich Text Field
CVE-2026-28360
NocoDB has Plaintext Storage of Shared View Passwords
CVE-2026-28398
NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells
CVE-2026-28358
NocoDB Vulnerable to User Enumeration via Password Reset Endpoint
CVE-2026-28401
NocoDB Vulnerable to Stored Cross-Site Scripting via Rich Text Cells
CVE-2026-28399
NocoDB Vulnerable to SQL Injection via DATEADD Formula
CVE-2026-24767
NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality
CVE-2026-24766
NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS
CVE-2026-24768
NocoDB has Unvalidated Redirect in Login Flow via continueAfterSignIn Parameter
CVE-2026-24769
NocoDB Vulnerable to Stored Cross-Site Scripting via SVG upload
CVE-2025-27506
NocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password Page
CVE-2023-50718
NocoDB SQL Injection vulnerability
CVE-2023-50717
NocoDB Allows Preview of Files with Dangerous Content
CVE-2023-49781
NocoDB Vulnerable to Stored Cross-Site Scripting in Formula.vue
CVE-2023-5104
Improper Input Validation in nocodb
CVE-2023-43794
nocodb SQL Injection vulnerability
CVE-2022-3423
NocoDB vulnerable to Denial of Service
CVE-2022-2079
Cross-site Scripting in NocoDB
CVE-2022-2064
Insufficient Session Expiration in NocoDB
CVE-2022-2063
Improper Privilege Management in NocoDB
CVE-2022-2062
NocoDB information disclosure vulnerability
Ready to move
Start Securing
Free, no credit card | First findings in minutes