Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1640 | NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a stored cross-site scripting vulnerability exists within the Formula virtual cell comments functionality. The nc-gui/components/virtual-cell/Formula.vue displays a v-html tag with the value of "urls" whose contents are processed by the function replaceUrlsWithLink(). This function recognizes the pattern URI::(XXX) and creates a hyperlink tag <a> with href=XXX. However, it leaves all the other contents outside of the pattern URI::(XXX) unchanged. This vulnerability is fixed in 0.202.9. |
Github GHSA |
GHSA-h6r4-xvw6-jc5h | NocoDB Vulnerable to Stored Cross-Site Scripting in Formula.vue |
Tue, 26 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xgenecloud
Xgenecloud nocodb |
Thu, 21 Aug 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xgenecloud
Xgenecloud nocodb |
|
| CPEs | cpe:2.3:a:xgenecloud:nocodb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xgenecloud
Xgenecloud nocodb |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T22:01:25.824Z
Reserved: 2023-11-30T13:39:50.861Z
Link: CVE-2023-49781
Updated: 2024-08-02T22:01:25.824Z
Status : Analyzed
Published: 2024-05-14T14:06:05.637
Modified: 2025-08-26T18:52:39.560
Link: CVE-2023-49781
No data.
OpenCVE Enrichment
Updated: 2025-07-12T16:01:18Z
EUVD
Github GHSA