Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48747
Total
3915
Critical
14448
High
14180
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73407 | UNKNOWN | — | Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials from getAuthHeaders and defaultHeaders without requiring the final request destination to … | Aug 12, 2026 |
| CVE-2026-73406 | HIGH | 7.5 | Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An … | Aug 12, 2026 |
| CVE-2026-73332 | HIGH | 8.7 | CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to … | Aug 12, 2026 |
| CVE-2026-73331 | HIGH | 7.1 | CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges to submit a crafted slug value containing … | Aug 12, 2026 |
| CVE-2026-73330 | MEDIUM | 6.6 | CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of … | Aug 12, 2026 |
| CVE-2026-73329 | HIGH | 8.7 | CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads … | Aug 12, 2026 |
| CVE-2026-73326 | HIGH | 7.6 | CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without … | Aug 12, 2026 |
| CVE-2026-73308 | MEDIUM | 5.7 | Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.outputs.user.oauth2, broadcast BuilderSocketEvent.AutomationTestProgress to the app room, and stored progress … | Aug 12, 2026 |
| CVE-2026-73307 | UNKNOWN | — | Budibase is an open-source low-code platform. Prior to 3.39.4, uploadUrl in packages/server/src/utilities/fileUtils.ts used a bare server-side fetch for string attachment values passed by processAttachments in … | Aug 12, 2026 |
| CVE-2026-73306 | MEDIUM | 5.3 | Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers/global/auth.ts only for existing users, while packages/worker/src/middleware/emailLockout.ts returned X-Account-Locked … | Aug 12, 2026 |
| CVE-2026-73303 | HIGH | 8.2 | Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while … | Aug 12, 2026 |
| CVE-2026-73269 | CRITICAL | 9.9 | A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation … | Aug 12, 2026 |
| CVE-2026-73268 | CRITICAL | 9.9 | A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an … | Aug 12, 2026 |
| CVE-2026-72809 | HIGH | 8.0 | SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any … | Aug 12, 2026 |
| CVE-2026-72808 | MEDIUM | 5.8 | SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endpoint, which returns .sya PDF-annotation file content … | Aug 12, 2026 |
| CVE-2026-72807 | HIGH | 8.0 | SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string … | Aug 12, 2026 |
| CVE-2026-72806 | MEDIUM | 5.8 | SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish password protection when rendering attribute views and … | Aug 12, 2026 |
| CVE-2026-72805 | MEDIUM | 5.8 | SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata. Anonymous readers … | Aug 12, 2026 |
| CVE-2026-72804 | HIGH | 8.6 | SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of password-protected documents. Attackers … | Aug 12, 2026 |
| CVE-2026-72803 | MEDIUM | 5.8 | SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve block attributes including names, aliases, memos, and … | Aug 12, 2026 |
| CVE-2026-72802 | MEDIUM | 5.3 | SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths unmodified to CheckAuth-only requests. Attackers can harvest … | Aug 12, 2026 |
| CVE-2026-72801 | HIGH | 7.5 | SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, … | Aug 12, 2026 |
| CVE-2026-72800 | MEDIUM | 5.8 | SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select … | Aug 12, 2026 |
| CVE-2026-72799 | MEDIUM | 5.8 | SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPathByID, getPathByID, getIDsByHPath, and getHPathByPath). In publish mode, when … | Aug 12, 2026 |
| CVE-2026-72798 | HIGH | 8.6 | SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or … | Aug 12, 2026 |