NocoBase
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 2, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →NocoBase backup restore schema name allows command injection
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
NocoBase 2.1.20 Server-Side Request Forgery via serverRequest wrapper
NocoBase Vulnerable to SQL Injection via String Concatenation in Recursive Eager Loading
NocoBase Vulnerable to SQL Validation Bypass via `sqlCollection:update` Missing `checkSQL` Call
NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins
NocoBase Has SQL Injection via template variable substitution in workflow SQL node
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
nocobase JWT Service jwt-service.ts hard-coded key
Monitor NocoBase in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.