Package impact

npm npm / nocodb

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2026-46552 medium 5.5 6d ago NocoDB: Shared-base link access can invite arbitrary users as persistent base members npm
CVE-2026-46551 medium 5.5 6d ago NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion npm
CVE-2026-46550 medium 5.5 6d ago NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags npm
CVE-2026-46548 medium 5.5 6d ago NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams) npm
CVE-2026-46547 medium 5.5 6d ago NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL npm
CVE-2026-46554 low 2.5 6d ago NocoDB: Stale Auth Cache After API Token Deletion npm
CVE-2026-46553 low 2.5 6d ago NocoDB: Attachment Size Limit Bypass via Upload-by-URL npm
CVE-2026-46549 low 2.5 6d ago NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation npm
CVE-2026-28401 unknown 3mo ago NocoDB Vulnerable to Stored Cross-Site Scripting via Rich Text Cells npm
CVE-2026-28397 unknown 3mo ago NocoDB Vulnerable to Stored Cross-site Scripting via Comments npm
CVE-2026-28399 unknown 3mo ago NocoDB Vulnerable to SQL Injection via DATEADD Formula npm
CVE-2026-28398 unknown 3mo ago NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells npm
CVE-2026-28361 unknown 3mo ago NocoDB Missing Ownership Validation in MCP Token Operations npm
CVE-2026-28396 unknown 3mo ago NocoDB's Refresh Tokens Not Revoked on Password Reset npm
CVE-2026-28360 unknown 3mo ago NocoDB has Plaintext Storage of Shared View Passwords npm
CVE-2026-28359 unknown 3mo ago NocoDB Vulnerable to Stored Cross-site Scripting via Rich Text Field npm
CVE-2026-28358 unknown 3mo ago NocoDB Vulnerable to User Enumeration via Password Reset Endpoint npm
CVE-2026-28357 unknown 3mo ago NocoDB has Stored Cross-site Scripting via Formula Cell npm
CVE-2026-24766 unknown 4mo ago NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS npm
CVE-2026-24767 unknown 4mo ago NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality susenpm
CVE-2026-24768 unknown 4mo ago NocoDB has Unvalidated Redirect in Login Flow via continueAfterSignIn Parameter npm
CVE-2026-24769 unknown 4mo ago NocoDB Vulnerable to Stored Cross-Site Scripting via SVG upload npm
CVE-2025-27506 unknown 1y ago NocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password Page npm
CVE-2023-49781 unknown 2y ago NocoDB Vulnerable to Stored Cross-Site Scripting in Formula.vue npm
CVE-2023-50718 unknown 2y ago NocoDB SQL Injection vulnerability npm
CVE-2023-50717 unknown 2y ago NocoDB Allows Preview of Files with Dangerous Content npm
CVE-2023-43794 unknown 3y ago nocodb SQL Injection vulnerability npm
CVE-2023-5104 unknown 3y ago Improper Input Validation in nocodb npm
CVE-2022-3423 unknown 4y ago NocoDB vulnerable to Denial of Service npm
CVE-2022-2079 unknown 4y ago Cross-site Scripting in NocoDB npm
CVE-2022-2063 unknown 4y ago Improper Privilege Management in NocoDB npm
CVE-2022-2064 unknown 4y ago Insufficient Session Expiration in NocoDB npm
CVE-2022-2062 unknown 4y ago NocoDB information disclosure vulnerability npm