In Django versions 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30 a medium severity vulnerability CVE-2026-33033 was detected. This vulnerability allows attackers to degrade server performance and cause denial of service (DoS) by sending multipart uploads with Content-Transfer-Encoding: base64 containing excessive whitespace, exploiting inefficiencies in the MultiPartParser. To address this issue, users should upgrade Django to versions 6.0.4, 5.2.13, or 4.2.30. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-33033.
Read more Application DevelopmentIn Budibase versions prior to 3.33.4 a high severity vulnerability CVE-2026-25044 was detected. This vulnerability allows attackers to execute arbitrary commands by injecting malicious input into the Bash automation step, which uses execSync without proper sanitization and processes user input through template interpolation. To address this issue, users should upgrade Budibase to version 3.33.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25044.
Read more Application DevelopmentIn BookStack versions up to 26.03 a medium severity vulnerability CVE-2026-5484 was detected. This vulnerability allows attackers to exploit improper access controls in the chapterToMarkdown function of the Chapter Export Handler by manipulating the pagesargument, potentially enabling unauthorized data access. To address this issue, users should upgrade BookStack to version 26.03.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5484.
Read more CMSIn Budibase versions prior to 3.32.5 a high severity vulnerability CVE-2026-35218 was detected. This vulnerability allows authenticated users with Builder access to execute stored cross-site scripting (XSS) by injecting malicious HTML into entity names, which are rendered without sanitization in the Builder Command Palette using the {@html} directive. This can lead to session hijacking and potential account takeover. To address this issue, users should upgrade Budibase to version 3.32.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-35218.
Read more Application DevelopmentIn Budibase versions prior to 3.33.4 a critical severity vulnerability CVE-2026-35216 was detected. This vulnerability allows unauthenticated attackers to achieve remote code execution (RCE) by triggering automations containing a Bash step through a public webhook endpoint, with commands executed as root inside the container. To address this issue, users should upgrade Budibase to version 3.33.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-35216.
Read more Application DevelopmentIn Budibase versions prior to 3.33.4 a critical severity vulnerability CVE-2026-31818 was detected. This vulnerability allows attackers to perform server-side request forgery (SSRF) due to ineffective IP blacklist enforcement in the REST datasource connector when the BLACKLIST_IPS environment variable is unset, allowing unrestricted outbound requests. To address this issue, users should upgrade Budibase to version 3.33.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-31818.
Read more Application DevelopmentIn Budibase versions prior to 3.33.4 a high severity vulnerability CVE-2026-35214 was detected. This vulnerability allows attackers with Global Builder privileges to perform path traversal attacks via the plugin file upload endpoint, enabling arbitrary directory deletion and file write by supplying crafted filenames containing traversal sequences. To address this issue, users should upgrade Budibase to version 3.33.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-35214.
Read more Application DevelopmentIn Alerta versions prior to 9.1.0 a medium severity vulnerability CVE-2026-34400 was detected. This vulnerability allows attackers to perform SQL injection via the query string search API (q=) due to unsafe interpolation of user-supplied input into SQL statements. To address this issue, users should upgrade Alerta to version 9.1.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-34400.
Read more MonitoringIn changedetection.io versions prior to 0.54.7 a medium severity vulnerability CVE-2026-33981 was detected. This vulnerability allows attackers to disclose sensitive environment variables by exploiting the jq: and jqraw: include filters, which permit use of the jq env builtin to read and expose process environment variables. To address this issue, users should upgrade changedetection.io to version 0.54.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-33981.
Read more Monitoring