Budibase is a low-code application-development platform with a concentrated footprint centered on its core product, which presents an attractive surface for server-side attacks given its role in building and hosting web applications. Its disclosed vulnerabilities skew strongly toward critical-severity outcomes and cluster around dangerous input-handling and resource-control weaknesses—including server-side request forgery, OS command injection, path traversal, cross-site scripting, and unthrottled resource allocation—that reflect the platform's exposure to untrusted user input across build pipelines and deployed applications. Defenders should prioritize patching instances of this vendor's platform, particularly internet-facing deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Budibase over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31816CRITICAL Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every s | Mar 9, 2026 | 9.1 | 51 | NO | YES |
CVE-2026-54350CRITICAL Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elas | Jun 26, 2026 | 9.8 | 44 | NO | NO |
CVE-2026-54352CRITICAL Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts | Jun 26, 2026 | 9.6 | 43 | NO | NO |
CVE-2026-54351CRITICAL Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation | Jun 26, 2026 | 9.6 | 42 | NO | NO |
CVE-2026-50137CRITICAL Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-source datasource id (ds_...) can | Jun 26, 2026 | 9.4 | 40 | NO | NO |
CVE-2026-35216CRITICAL Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an a | Apr 3, 2026 | 9.0 | 38 | NO | NO |
CVE-2026-54353HIGH Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding. The outbo | Jun 26, 2026 | 7.1 | 35 | NO | NO |
CVE-2026-41428CRITICAL Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoint patterns against | Apr 24, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-31818CRITICAL Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platfo | Apr 3, 2026 | 9.9 | 34 | NO | NO |
CVE-2026-50132HIGH Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required) that performs a permanent, sta | Jun 26, 2026 | 7.3 | 33 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Budibase.
Media articles that mention a CVE ID that affects a product developed by Budibase — matched by CVE ID, not by vendor name.