Budibase
71 CVEs tracked since 2026. Since Apr 2026, none of them reached CISA KEV.
Budibase CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-04 | 7 | 0 |
| 2026-05 | 21 | 0 |
| 2026-06 | 7 | 0 |
| 2026-07 | null or fewer | |
| 2026-08 | 36 | 0 |
Products
The products that kept showing up in Budibase's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Budibase.
- CVE-2026-100688Budibase server before 3.45.0 Cross-Tenant Information Disclosure6.5
- CVE-2026-100687Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast5.5
- CVE-2026-100686Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:groupId/apps8.1
- CVE-2026-100684Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC8.1
- CVE-2026-100685Budibase before 3.45.0 Information Disclosure via Chat Links7.7
- CVE-2026-100683Budibase before 3.45.0 SQL Injection via column-rename DDL8.0
- CVE-2026-100681Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook5.4
- CVE-2026-100682Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink8.8
- CVE-2026-100680Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import8.1
- CVE-2026-82245Budibase before 3.41.3 Missing Authorization License Management8.1
- CVE-2026-82246Budibase Server before 3.41.3 SSRF via Query Import7.1
- CVE-2026-82244Budibase before 3.41.3 Remote Code Execution via Plugin eval()9.1
- CVE-2026-82243Budibase Server before 3.41.3 SSRF with Credential Leakage7.6
- CVE-2026-82242Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization7.7
- CVE-2026-82241Budibase backend-core SSRF via incomplete default blacklist7.1
The record
- Peak rank
- #34 in Aug 2026
- Busiest month shown
- Aug 2026, 36 CVEs
- Months with a KEV entry
- 0 since Apr 2026
- Monthly snapshots
- 4 since 2026