Technology · npm
nocodb (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 55 vulnerabilities in nocodb (npm): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-53931, was published on 23 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About nocodb (npm)
An open-source no-code database platform that turns any database into a smart spreadsheet.
Latest nocodb (npm) vulnerabilities
- CVE-2026-53931: NocoDB SSRF in spreadsheet-import endpointmediumCVSS 4EPSS 0.4%
- CVE-2026-53930: NocoDB SSRF in base-migration endpointmediumCVSS 4EPSS 0.4%
- CVE-2026-53929: NocoDB stored cross-site scripting in secure attachmentsmediumCVSS 4EPSS 0.4%
- CVE-2026-53928: NocoDB insufficient session expiration in password recovery flowmediumCVSS 4EPSS 0.3%
- CVE-2026-53927: NocoDB SSRF in spreadsheet-fetch endpointmediumCVSS 4EPSS 0.4%
- CVE-2026-53926: NocoDB insufficient session expiration in OAuth token revocationmediumCVSS 4EPSS 0.4%
- CVE-2026-47388: NocoDB authorization bypass in MCP readAttachment toolmediumCVSS 4EPSS 0.3%
- CVE-2026-47387: NocoDB stored XSS in shared form-view redirect URLhighCVSS 4EPSS 0.4%
- CVE-2026-47386: NocoDB OAuth authorization code race conditionmediumCVSS 4EPSS 0.3%
- CVE-2026-47385: NocoDB path traversal in SQLite source integrationmediumCVSS 4EPSS 0.4%
- CVE-2026-47384: NocoDB SQL injection in bulk groupBy via column titlemediumCVSS 4EPSS 0.4%
- CVE-2026-47383: NocoDB stored XSS in row commentshighCVSS 4EPSS 0.4%
- CVE-2026-47382: NocoDB Server-Side Request Forgery in connection-test endpointmediumCVSS 4EPSS 0.4%
- CVE-2026-47381: NocoDB authorization bypass in testConnection endpointmediumCVSS 4EPSS 0.4%
- CVE-2026-47380: NocoDB user enumeration via sign-in timing discrepancymediumCVSS 4EPSS 0.3%
- CVE-2026-47379: NocoDB timing attack in shared-view password checkmediumCVSS 4EPSS 0.4%
- CVE-2026-47378: NocoDB information disclosure in public shared-view endpointsmediumCVSS 4EPSS 0.4%
- CVE-2026-47377: NocoDB open redirect in hashRedirect pluginmediumCVSS 4EPSS 0.4%
- CVE-2026-47376: NocoDB reflected XSS in password-reset pagemediumCVSS 4EPSS 0.4%
- CVE-2026-47375: NocoDB SQL injection in ARRAYSORT formula for PostgreSQLmediumCVSS 6EPSS 0.4%
- CVE-2026-47279: NocoDB improper access control in public shared-view relation endpointsmediumCVSS 4EPSS 0.4%
- CVE-2026-46554: NocoDB stale authentication cache after API token deletionmediumCVSS 4EPSS 0.3%
- CVE-2026-46553: NocoDB attachment size limit bypass in upload-by-URLmediumCVSS 4EPSS 0.4%
- CVE-2026-46552: NocoDB improper authorization in shared-base sessionsmediumCVSS 5.8EPSS 0.3%
- CVE-2026-46551: NocoDB denial of service via disk exhaustion in attachment APImediumCVSS 6.5EPSS 0.4%
Most severe nocodb (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-47387: NocoDB stored XSS in shared form-view redirect URLhighCVSS 4EPSS 0.4%
- CVE-2026-47383: NocoDB stored XSS in row commentshighCVSS 4EPSS 0.4%
- CVE-2026-46551: NocoDB denial of service via disk exhaustion in attachment APImediumCVSS 6.5EPSS 0.4%
- NocoDB insufficient session expiration for OAuth tokensmediumCVSS 6.3
- CVE-2026-46547: NocoDB reflected XSS in Page Leaving Warning pagemediumCVSS 6.1EPSS 0.3%
- CVE-2026-47375: NocoDB SQL injection in ARRAYSORT formula for PostgreSQLmediumCVSS 6EPSS 0.4%
- CVE-2026-46552: NocoDB improper authorization in shared-base sessionsmediumCVSS 5.8EPSS 0.3%
- CVE-2026-46550: NocoDB missing Secure and SameSite flags in refresh-token cookiemediumCVSS 5.4EPSS 0.2%
- CVE-2026-46548: NocoDB SSRF protection bypass in notification webhook pluginsmediumCVSS 4.3EPSS 0.3%
- CVE-2026-28358: NocoDB user enumeration via password reset endpointmediumCVSS 4EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/nocodb.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "nocodb (npm) vulnerabilities", https://junglewise.ai/threats/technologies/nocodb, 26 September 2026.