@budibase/server

Budibase Web Server
Licenses: AGPL-3.0 | GPL-3.0

License

>=0.0.1 <0.0.999-alpha.30;
>=0.1.0 <0.9.188;
>=0.0.0 <0.0.1;
>=0.0.999-alpha.30 <0.1.0;
>=0.9.188;

Direct Vulnerabilities

Known vulnerabilities in the @budibase/server package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
SQL Injection

*
  • M
Information Exposure

*
  • H
Cross-site Request Forgery (CSRF)

*
  • H
Incorrect Authorization

*
  • H
Authorization Bypass Through User-Controlled Key

*
  • M
Server-side Request Forgery (SSRF)

*
  • M
Information Exposure

*
  • H
SQL Injection

*
  • H
Improper Neutralization of Special Elements in Data Query Logic

>=0.0.0
  • H
Information Exposure

>=0.0.0
  • H
Server-side Request Forgery (SSRF)

>=0.0.0
  • H
Incorrect Authorization

>=0.0.0
  • H
SQL Injection

>=0.0.0
  • H
Server-side Request Forgery (SSRF)

>=0.0.0
  • M
Information Exposure

>=0.0.0
  • M
Server-side Request Forgery (SSRF)

*
  • H
SQL Injection

*
  • H
Arbitrary File Upload

*
  • C
Improper Neutralization of Special Elements in Data Query Logic

<3.38.1
  • M
Missing Authorization

*
  • H
Cross-site Request Forgery (CSRF)

*
  • H
Symlink Attack

*
  • H
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<3.38.1
  • H
Missing Authorization

*
  • H
Server-side Request Forgery (SSRF)

<3.38.1
  • H
Missing Authorization

*
  • M
Server-side Request Forgery (SSRF)

<3.35.3
  • H
Incorrect Authorization

<3.38.1
  • H
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • H
Server-side Request Forgery (SSRF)

<3.38.1
  • M
Incorrect Authorization

<3.38.1
  • H
Arbitrary Code Injection

<3.38.1
  • M
Server-side Request Forgery (SSRF)

<3.38.1
  • M
Server-side Request Forgery (SSRF)

<3.34.8
  • H
Missing Authorization

<3.38.1
  • M
Server-side Request Forgery (SSRF)

<3.35.10
  • H
Command Injection

<3.33.4
  • C
Command Injection

<3.33.4
  • H
Directory Traversal

<3.33.4
  • C
Server-side Request Forgery (SSRF)

<3.34.8
  • H
Eval Injection

<3.30.4

Package versions

3142 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
3.38.112 May, 2026
  • 0
    C
  • 18
    H
  • 6
    M
  • 0
    L
3.38.07 May, 2026
  • 1
    C
  • 24
    H
  • 8
    M
  • 0
    L
3.37.57 May, 2026
  • 1
    C
  • 24
    H
  • 8
    M
  • 0
    L
3.37.45 May, 2026
  • 1
    C
  • 24
    H
  • 8
    M
  • 0
    L
3.37.34 May, 2026
  • 1
    C
  • 24
    H
  • 8
    M
  • 0
    L
3.37.230 Apr, 2026
  • 1
    C
  • 24
    H
  • 8
    M
  • 0
    L
3.37.129 Apr, 2026
  • 1
    C
  • 24
    H
  • 8
    M
  • 0
    L
3.37.028 Apr, 2026
  • 1
    C
  • 24
    H
  • 8
    M
  • 0
    L
3.36.527 Apr, 2026
  • 1
    C
  • 24
    H
  • 8
    M
  • 0
    L
3.36.427 Apr, 2026
  • 1
    C
  • 24
    H
  • 8
    M
  • 0
    L