Saltcorn is a low-code web-application platform whose limited disclosure footprint concentrates on a single product and revolves around application-layer input-handling issues: path traversal and SQL injection vulnerabilities reflecting the classic attack surface of database-backed web frameworks. Current severity, exploitation status, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Saltcorn over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41478CRITICAL Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcorn’s mobile-sync route | Apr 24, 2026 | 9.9 | 37 | NO | NO |
CVE-2026-40163HIGH Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, the POST /sync/offline_changes endpoint allows an unauthentic | Apr 10, 2026 | 8.2 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Saltcorn.
Media articles that mention a CVE ID that affects a product developed by Saltcorn — matched by CVE ID, not by vendor name.