Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Budibase

First CVE: Sep 16, 2022Active for: 4 yearsTotal CVEs: 25
64.5
VTI Score
TOP TARGET

Budibase is a low-code application-development platform with a concentrated footprint centered on its core product, which presents an attractive surface for server-side attacks given its role in building and hosting web applications. Its disclosed vulnerabilities skew strongly toward critical-severity outcomes and cluster around dangerous input-handling and resource-control weaknesses—including server-side request forgery, OS command injection, path traversal, cross-site scripting, and unthrottled resource allocation—that reflect the platform's exposure to untrusted user input across build pipelines and deployed applications. Defenders should prioritize patching instances of this vendor's platform, particularly internet-facing deployments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
8.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Budibase over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2022
3 years ago
Most Recent CVE
Jun 26, 2026
28 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-31816CRITICAL
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every s
Mar 9, 20269.151NOYES
CVE-2026-54350CRITICAL
Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elas
Jun 26, 20269.844NONO
CVE-2026-54352CRITICAL
Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts
Jun 26, 20269.643NONO
CVE-2026-54351CRITICAL
Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation
Jun 26, 20269.642NONO
CVE-2026-50137CRITICAL
Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-source datasource id (ds_...) can
Jun 26, 20269.440NONO
CVE-2026-35216CRITICAL
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an a
Apr 3, 20269.038NONO
CVE-2026-54353HIGH
Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding. The outbo
Jun 26, 20267.135NONO
CVE-2026-41428CRITICAL
Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoint patterns against
Apr 24, 20269.135NONO
CVE-2026-31818CRITICAL
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platfo
Apr 3, 20269.934NONO
CVE-2026-50132HIGH
Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required) that performs a permanent, sta
Jun 26, 20267.333NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
12%
48%
40%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (92.0%)
High2 (8.0%)
Unknown0 (0.0%)
User Interaction
None19 (76.0%)
Unknown0 (0.0%)
Required6 (24.0%)
Privileges Required
Low14 (56.0%)
High4 (16.0%)
None7 (28.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.0% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Budibase.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Budibase — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Budibase's Products

View all 2 CNAs →

Top CWEs