{"schema_version":1,"title":"Nocobase vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 13 vulnerabilities in Nocobase: 1 in the last 7 days and 7 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-88402, was published on 21 September 2026.","url":"https://junglewise.ai/threats/technologies/nocobase","json_url":"https://junglewise.ai/threats/technologies/nocobase.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/nocobase","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":13,"critical":3,"exploited":0,"last_7_days":1,"last_30_days":2,"last_90_days":7,"last_365_days":13},"latest":[{"cve":"CVE-2026-88402","cvss":9.8,"epss":0.0047,"slug":"cve-2026-88402-a-sql-injection-vulnerability-in-the-checksql-function-of","title":"NocoBase SQL injection in checkSQL function","severity":"critical","exploited":false,"published_at":"2026-09-21T21:17:14.273+00:00","url":"https://junglewise.ai/threats/cve-2026-88402-a-sql-injection-vulnerability-in-the-checksql-function-of"},{"cve":"CVE-2026-84701","cvss":5.4,"epss":0.003,"slug":"cve-2026-84701-nocobase-cross-site-scripting-in-rich-text-field-renderer","title":"NocoBase cross-site scripting in rich text field renderer","severity":"medium","exploited":false,"published_at":"2026-09-02T01:17:25.287+00:00","url":"https://junglewise.ai/threats/cve-2026-84701-nocobase-cross-site-scripting-in-rich-text-field-renderer"},{"cvss":8.8,"slug":"nocobase-arbitrary-file-write-and-local-file-inclusion-leading-to-b8ec6b22","title":"NocoBase arbitrary file write and local file inclusion leading to remote code execution","severity":"info","exploited":false,"published_at":"2026-08-20T18:42:21+00:00","url":"https://junglewise.ai/threats/nocobase-arbitrary-file-write-and-local-file-inclusion-leading-to-b8ec6b22"},{"cvss":8.8,"slug":"nocobase-arbitrary-file-write-and-local-file-inclusion-leading-to-c46c0c58","title":"NocoBase arbitrary file write and local file inclusion leading to remote code execution","severity":"high","exploited":false,"published_at":"2026-08-20T18:42:21+00:00","url":"https://junglewise.ai/threats/nocobase-arbitrary-file-write-and-local-file-inclusion-leading-to-c46c0c58"},{"cve":"CVE-2026-52888","cvss":6.8,"epss":0.0047,"slug":"cve-2026-52888-nocobase-sensitive-data-exposure-via-sql-blacklist-bypass-in-sql","title":"NocoBase sensitive data exposure via SQL blacklist bypass in SQL Collection","severity":"medium","exploited":false,"published_at":"2026-07-15T21:16:54.673+00:00","url":"https://junglewise.ai/threats/cve-2026-52888-nocobase-sensitive-data-exposure-via-sql-blacklist-bypass-in-sql"},{"cve":"CVE-2026-52887","cvss":10,"epss":0.0089,"slug":"cve-2026-52887-nocobase-sql-injection-in-in-app-notification-channel-filter","title":"NocoBase SQL injection in in-app notification channel filter","severity":"critical","exploited":false,"published_at":"2026-07-15T21:16:54.543+00:00","url":"https://junglewise.ai/threats/cve-2026-52887-nocobase-sql-injection-in-in-app-notification-channel-filter"},{"cve":"CVE-2026-58468","cvss":5.5,"slug":"cve-2026-58468-nocobase-ssrf-in-serverrequest-wrapper","title":"NocoBase SSRF in serverRequest wrapper","severity":"medium","exploited":false,"published_at":"2026-07-07T20:16:29.24+00:00","url":"https://junglewise.ai/threats/cve-2026-58468-nocobase-ssrf-in-serverrequest-wrapper"},{"cve":"CVE-2026-41640","cvss":7.5,"epss":0.0242,"slug":"cve-2026-41640-nocobase-sql-injection-in-recursive-eager-loading","title":"NocoBase SQL injection in recursive eager loading","severity":"high","exploited":false,"published_at":"2026-05-07T04:16:28.277+00:00","url":"https://junglewise.ai/threats/cve-2026-41640-nocobase-sql-injection-in-recursive-eager-loading"},{"cve":"CVE-2026-40346","cvss":6.5,"epss":0.0043,"slug":"cve-2026-40346-nocobase-has-ssrf-in-workflow-http-request-and-custom-request","title":"NocoBase SSRF in Workflow and Custom Request plugins","severity":"medium","exploited":false,"published_at":"2026-04-18T00:16:38.36+00:00","url":"https://junglewise.ai/threats/cve-2026-40346-nocobase-has-ssrf-in-workflow-http-request-and-custom-request"},{"cve":"CVE-2026-34825","cvss":6.5,"epss":0.005,"slug":"cve-2026-34825-nocobase-sql-injection-in-workflow-sql-node","title":"NocoBase SQL injection in workflow SQL node","severity":"medium","exploited":false,"published_at":"2026-04-02T20:16:26.247+00:00","url":"https://junglewise.ai/threats/cve-2026-34825-nocobase-sql-injection-in-workflow-sql-node"},{"cve":"CVE-2026-34156","cvss":9.9,"epss":0.0679,"slug":"cve-2026-34156-nocobase-sandbox-escape-and-rce-in-workflow-script-node","title":"NocoBase sandbox escape and RCE in Workflow Script Node","severity":"critical","exploited":false,"published_at":"2026-03-31T14:16:12.17+00:00","url":"https://junglewise.ai/threats/cve-2026-34156-nocobase-sandbox-escape-and-rce-in-workflow-script-node"},{"cvss":3.1,"slug":"nocobase-authentication-bypass-via-default-jwt-secret-30be146c","title":"NocoBase authentication bypass via default JWT secret","severity":"low","exploited":false,"published_at":"2025-12-02T18:30:35+00:00","url":"https://junglewise.ai/threats/nocobase-authentication-bypass-via-default-jwt-secret-30be146c"},{"cve":"CVE-2025-13877","cvss":5.6,"epss":0.003,"slug":"cve-2025-13877-nocobase-authentication-bypass-via-default-jwt-secret","title":"A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\\packag","severity":"medium","exploited":false,"published_at":"2025-12-02T16:15:54.31+00:00","url":"https://junglewise.ai/threats/cve-2025-13877-nocobase-authentication-bypass-via-default-jwt-secret"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":1}],"related":[],"technology":{"hub":true,"name":"Nocobase","slug":"nocobase","vendor":{"name":"NocoBase","slug":"nocobase","url":"https://junglewise.ai/threats/vendors/nocobase"},"aliases":[],"category":"cms","homepage":"https://www.nocobase.com/","repo_url":"https://github.com/nocobase/nocobase","description":"Open-source no-code database platform and collaborative API builder.","url":"https://junglewise.ai/threats/technologies/nocobase"},"most_severe":[{"cve":"CVE-2026-52887","cvss":10,"epss":0.0089,"slug":"cve-2026-52887-nocobase-sql-injection-in-in-app-notification-channel-filter","title":"NocoBase SQL injection in in-app notification channel filter","severity":"critical","exploited":false,"published_at":"2026-07-15T21:16:54.543+00:00","url":"https://junglewise.ai/threats/cve-2026-52887-nocobase-sql-injection-in-in-app-notification-channel-filter"},{"cve":"CVE-2026-34156","cvss":9.9,"epss":0.0679,"slug":"cve-2026-34156-nocobase-sandbox-escape-and-rce-in-workflow-script-node","title":"NocoBase sandbox escape and RCE in Workflow Script Node","severity":"critical","exploited":false,"published_at":"2026-03-31T14:16:12.17+00:00","url":"https://junglewise.ai/threats/cve-2026-34156-nocobase-sandbox-escape-and-rce-in-workflow-script-node"},{"cve":"CVE-2026-88402","cvss":9.8,"epss":0.0047,"slug":"cve-2026-88402-a-sql-injection-vulnerability-in-the-checksql-function-of","title":"NocoBase SQL injection in checkSQL function","severity":"critical","exploited":false,"published_at":"2026-09-21T21:17:14.273+00:00","url":"https://junglewise.ai/threats/cve-2026-88402-a-sql-injection-vulnerability-in-the-checksql-function-of"},{"cvss":8.8,"slug":"nocobase-arbitrary-file-write-and-local-file-inclusion-leading-to-c46c0c58","title":"NocoBase arbitrary file write and local file inclusion leading to remote code execution","severity":"high","exploited":false,"published_at":"2026-08-20T18:42:21+00:00","url":"https://junglewise.ai/threats/nocobase-arbitrary-file-write-and-local-file-inclusion-leading-to-c46c0c58"},{"cve":"CVE-2026-41640","cvss":7.5,"epss":0.0242,"slug":"cve-2026-41640-nocobase-sql-injection-in-recursive-eager-loading","title":"NocoBase SQL injection in recursive eager loading","severity":"high","exploited":false,"published_at":"2026-05-07T04:16:28.277+00:00","url":"https://junglewise.ai/threats/cve-2026-41640-nocobase-sql-injection-in-recursive-eager-loading"},{"cve":"CVE-2026-52888","cvss":6.8,"epss":0.0047,"slug":"cve-2026-52888-nocobase-sensitive-data-exposure-via-sql-blacklist-bypass-in-sql","title":"NocoBase sensitive data exposure via SQL blacklist bypass in SQL Collection","severity":"medium","exploited":false,"published_at":"2026-07-15T21:16:54.673+00:00","url":"https://junglewise.ai/threats/cve-2026-52888-nocobase-sensitive-data-exposure-via-sql-blacklist-bypass-in-sql"},{"cve":"CVE-2026-34825","cvss":6.5,"epss":0.005,"slug":"cve-2026-34825-nocobase-sql-injection-in-workflow-sql-node","title":"NocoBase SQL injection in workflow SQL node","severity":"medium","exploited":false,"published_at":"2026-04-02T20:16:26.247+00:00","url":"https://junglewise.ai/threats/cve-2026-34825-nocobase-sql-injection-in-workflow-sql-node"},{"cve":"CVE-2026-40346","cvss":6.5,"epss":0.0043,"slug":"cve-2026-40346-nocobase-has-ssrf-in-workflow-http-request-and-custom-request","title":"NocoBase SSRF in Workflow and Custom Request plugins","severity":"medium","exploited":false,"published_at":"2026-04-18T00:16:38.36+00:00","url":"https://junglewise.ai/threats/cve-2026-40346-nocobase-has-ssrf-in-workflow-http-request-and-custom-request"},{"cve":"CVE-2025-13877","cvss":5.6,"epss":0.003,"slug":"cve-2025-13877-nocobase-authentication-bypass-via-default-jwt-secret","title":"A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\\packag","severity":"medium","exploited":false,"published_at":"2025-12-02T16:15:54.31+00:00","url":"https://junglewise.ai/threats/cve-2025-13877-nocobase-authentication-bypass-via-default-jwt-secret"},{"cve":"CVE-2026-58468","cvss":5.5,"slug":"cve-2026-58468-nocobase-ssrf-in-serverrequest-wrapper","title":"NocoBase SSRF in serverRequest wrapper","severity":"medium","exploited":false,"published_at":"2026-07-07T20:16:29.24+00:00","url":"https://junglewise.ai/threats/cve-2026-58468-nocobase-ssrf-in-serverrequest-wrapper"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}