Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7786 | NocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password Page |
Github GHSA |
GHSA-wf6c-hrhf-86cw | NocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password Page |
Tue, 26 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nocodb
Nocodb nocodb |
|
| CPEs | cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xgenecloud
Xgenecloud nocodb |
Nocodb
Nocodb nocodb |
Mon, 25 Aug 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xgenecloud
Xgenecloud nocodb |
|
| CPEs | cpe:2.3:a:xgenecloud:nocodb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xgenecloud
Xgenecloud nocodb |
Thu, 06 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Mar 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId is vulnerable to Reflected Cross-Site-Scripting. The flaw occurs due to implementation of the client-side template engine ejs, specifically on file resetPassword.ts where the template is using the insecure function “<%-“, which is rendered by the function renderPasswordReset. This vulnerability is fixed in 0.258.0. | |
| Title | NocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password Page | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-06T19:19:39.656Z
Reserved: 2025-02-26T18:11:52.305Z
Link: CVE-2025-27506
Updated: 2025-03-06T19:19:17.047Z
Status : Analyzed
Published: 2025-03-06T19:15:27.833
Modified: 2025-08-26T18:52:47.833
Link: CVE-2025-27506
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA