{"api_version":"v1","generated_at":"2026-10-08T07:15:00+00:00","product":{"cve_count":66,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-budibase-budibase-e44aacc852ab","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/budibase","name":"budibase","next_cursor":"djE6NTA","observations":[{"affected":"budibase: < 3.41.0","affected_versions_present":true,"cve_id":"CVE-2026-103757","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-103757","fixed":"budibase: 3.41.0","last_modified":"2026-10-01T13:21:55.140Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-3c52-v5v2-3r56","primary_source":"","published":"2026-10-01T10:42:25.919Z"},{"affected":"< 3.41.3","affected_versions_present":true,"cve_id":"CVE-2026-54356","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54356","fixed":"3.41.3.","last_modified":"2026-08-18T13:33:04.062Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-6x9p-4r67-5gjx","primary_source":"","published":"2026-08-17T20:32:05.691Z"},{"affected":"< 3.41.3","affected_versions_present":true,"cve_id":"CVE-2026-35219","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35219","fixed":"3.41.3.","last_modified":"2026-08-18T12:37:02.273Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-5fpj-28rv-84r7","primary_source":"","published":"2026-08-17T20:28:40.828Z"},{"affected":"< 3.40.0","affected_versions_present":true,"cve_id":"CVE-2026-73410","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73410","fixed":"3.40.0.","last_modified":"2026-08-17T22:01:01.232Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-v42f-v8xc-j435","primary_source":"","published":"2026-08-17T20:27:24.080Z"},{"affected":"< 3.39.19","affected_versions_present":true,"cve_id":"CVE-2026-64657","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-64657","fixed":"3.39.19.","last_modified":"2026-08-18T15:30:33.751Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-qqf5-x7mj-v43p","primary_source":"","published":"2026-08-17T20:24:59.700Z"},{"affected":"< 3.39.24","affected_versions_present":true,"cve_id":"CVE-2026-73305","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73305","fixed":"3.39.24.","last_modified":"2026-08-18T01:46:32.727Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-j9fc-w3mr-x6mv","primary_source":"","published":"2026-08-13T22:05:02.972Z"},{"affected":"< 3.39.25","affected_versions_present":true,"cve_id":"CVE-2026-73304","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73304","fixed":"3.39.25.","last_modified":"2026-08-14T15:09:18.395Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-fcrw-f7gg-6g9f","primary_source":"","published":"2026-08-13T22:05:00.355Z"},{"affected":"< 3.39.18","affected_versions_present":true,"cve_id":"CVE-2026-73408","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73408","fixed":"3.39.18.","last_modified":"2026-08-14T18:06:29.345Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-2xgg-r2wc-c5r2","primary_source":"","published":"2026-08-13T22:04:53.979Z"},{"affected":"< 3.39.30","affected_versions_present":true,"cve_id":"CVE-2026-73302","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73302","fixed":"3.39.30.","last_modified":"2026-08-14T16:10:42.639Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-hp6v-6jw7-gv2f","primary_source":"","published":"2026-08-13T22:04:50.179Z"},{"affected":"< 3.40.0","affected_versions_present":true,"cve_id":"CVE-2026-72857","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-72857","fixed":"3.40.0","last_modified":"2026-08-14T16:12:55.091Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-6mpp-gfg5-x2vv","primary_source":"","published":"2026-08-13T21:54:45.984Z"},{"affected":"< 3.40.0","affected_versions_present":true,"cve_id":"CVE-2026-72856","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-72856","fixed":"3.40.0","last_modified":"2026-08-17T16:09:39.599Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-j82g-67x3-xcwh","primary_source":"","published":"2026-08-13T21:54:45.304Z"},{"affected":"< 3.40.0","affected_versions_present":true,"cve_id":"CVE-2026-72853","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-72853","fixed":"3.40.0","last_modified":"2026-08-18T01:43:22.355Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-xj29-x47g-9w2c","primary_source":"","published":"2026-08-13T21:54:43.945Z"},{"affected":"< 3.40.1","affected_versions_present":true,"cve_id":"CVE-2026-73409","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73409","fixed":"3.40.1.","last_modified":"2026-08-14T22:09:19.072Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-ppr4-5f46-j9c6","primary_source":"","published":"2026-08-12T19:19:59.492Z"},{"affected":"< 3.40.1","affected_versions_present":true,"cve_id":"CVE-2026-73407","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73407","fixed":"3.40.1.","last_modified":"2026-08-12T19:30:27.096Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-mqhr-6j6h-74p5","primary_source":"","published":"2026-08-12T19:09:55.799Z"},{"affected":"< 3.39.32","affected_versions_present":true,"cve_id":"CVE-2026-73406","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73406","fixed":"3.39.32.","last_modified":"2026-08-13T14:07:05.692Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-hr66-5mqr-8mpx","primary_source":"","published":"2026-08-12T19:03:51.766Z"},{"affected":"< 3.39.25","affected_versions_present":true,"cve_id":"CVE-2026-73308","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73308","fixed":"3.39.25.","last_modified":"2026-08-14T21:55:19.960Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-gh4h-34gr-87r7","primary_source":"","published":"2026-08-12T19:01:15.182Z"},{"affected":"< 3.39.4","affected_versions_present":true,"cve_id":"CVE-2026-73307","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73307","fixed":"3.39.4.","last_modified":"2026-08-12T19:46:08.763Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-hfhx-w8p8-4hc7","primary_source":"","published":"2026-08-12T18:59:52.011Z"},{"affected":"< 3.39.25","affected_versions_present":true,"cve_id":"CVE-2026-73306","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73306","fixed":"3.39.25.","last_modified":"2026-08-13T12:18:51.707Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-cr7p-cr3q-h5cm","primary_source":"","published":"2026-08-12T18:56:08.322Z"},{"affected":"< 3.40.0","affected_versions_present":true,"cve_id":"CVE-2026-73303","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73303","fixed":"3.40.0.","last_modified":"2026-08-12T22:11:41.829Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-c8vc-7pv3-g98p","primary_source":"","published":"2026-08-12T18:51:38.748Z"},{"affected":"< 3.39.2","affected_versions_present":true,"cve_id":"CVE-2026-73301","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73301","fixed":"3.39.25.","last_modified":"2026-08-14T21:53:29.056Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-4qcj-m5wp-jmf4","primary_source":"","published":"2026-08-12T18:08:07.998Z"},{"affected":"< 3.40.0","affected_versions_present":true,"cve_id":"CVE-2026-73300","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73300","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-12T18:55:16.387Z","patch_url":"","primary_source":"","published":"2026-08-12T18:05:51.428Z"},{"affected":"< 3.38.1","affected_versions_present":true,"cve_id":"CVE-2026-67311","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-67311","fixed":"3.38.1","last_modified":"2026-08-03T15:15:47.466Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-86f3-cqpq-wp9m","primary_source":"","published":"2026-08-01T12:22:18.316Z"},{"affected":"< 3.39.9","affected_versions_present":true,"cve_id":"CVE-2026-54351","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54351","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-29T15:19:57.939Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-rgvg-3wpc-h44p","primary_source":"","published":"2026-06-26T20:45:35.017Z"},{"affected":"< 3.39.9","affected_versions_present":true,"cve_id":"CVE-2026-54353","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54353","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-29T13:17:32.753Z","patch_url":"","primary_source":"","published":"2026-06-26T20:44:52.069Z"},{"affected":"< 3.39.12","affected_versions_present":true,"cve_id":"CVE-2026-54350","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54350","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-30T19:31:58.021Z","patch_url":"","primary_source":"","published":"2026-06-26T20:44:00.337Z"},{"affected":"< 3.39.0","affected_versions_present":true,"cve_id":"CVE-2026-50137","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50137","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-29T13:18:45.580Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-35c4-rvc8-frhm","primary_source":"","published":"2026-06-26T20:41:03.443Z"},{"affected":"< 3.39.3","affected_versions_present":true,"cve_id":"CVE-2026-50136","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50136","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-27T03:14:40.644Z","patch_url":"","primary_source":"","published":"2026-06-26T20:36:54.016Z"},{"affected":"< 3.39.0","affected_versions_present":true,"cve_id":"CVE-2026-50132","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50132","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-29T15:20:06.752Z","patch_url":"https://github.com/Budibase/budibase/security/advisories/GHSA-v7j5-vc4m-723w","primary_source":"","published":"2026-06-26T20:34:30.304Z"},{"affected":"< 3.39.9","affected_versions_present":true,"cve_id":"CVE-2026-54352","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54352","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-27T03:12:11.845Z","patch_url":"","primary_source":"","published":"2026-06-26T20:32:51.458Z"},{"affected":"< 3.35.4","affected_versions_present":true,"cve_id":"CVE-2026-48147","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48147","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T18:32:17.031Z","patch_url":"","primary_source":"","published":"2026-05-27T17:14:17.039Z"},{"affected":"< 3.35.3","affected_versions_present":true,"cve_id":"CVE-2026-48148","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48148","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T18:01:09.551Z","patch_url":"","primary_source":"","published":"2026-05-27T17:12:31.069Z"},{"affected":"< 3.34.8","affected_versions_present":true,"cve_id":"CVE-2026-45548","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45548","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T19:15:30.227Z","patch_url":"","primary_source":"","published":"2026-05-27T17:11:42.679Z"},{"affected":"< 3.38.1","affected_versions_present":true,"cve_id":"CVE-2026-45715","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45715","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T14:02:17.420Z","patch_url":"","primary_source":"","published":"2026-05-27T17:10:53.806Z"},{"affected":"< 3.38.1","affected_versions_present":true,"cve_id":"CVE-2026-45716","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45716","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T18:34:27.255Z","patch_url":"","primary_source":"","published":"2026-05-27T17:09:43.383Z"},{"affected":"< 3.38.1","affected_versions_present":true,"cve_id":"CVE-2026-45717","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45717","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T17:57:08.153Z","patch_url":"","primary_source":"","published":"2026-05-27T17:09:06.610Z"},{"affected":"< 3.38.1","affected_versions_present":true,"cve_id":"CVE-2026-45718","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45718","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T15:08:02.758Z","patch_url":"","primary_source":"","published":"2026-05-27T17:07:59.856Z"},{"affected":"< 3.38.1","affected_versions_present":true,"cve_id":"CVE-2026-45719","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45719","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T18:36:23.178Z","patch_url":"","primary_source":"","published":"2026-05-27T17:07:20.961Z"},{"affected":"< 3.38.2","affected_versions_present":true,"cve_id":"CVE-2026-46425","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46425","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T18:46:31.717Z","patch_url":"","primary_source":"","published":"2026-05-27T17:06:36.081Z"},{"affected":"< 3.38.2","affected_versions_present":true,"cve_id":"CVE-2026-46424","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46424","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T14:08:42.106Z","patch_url":"","primary_source":"","published":"2026-05-27T17:05:21.894Z"},{"affected":"< 3.38.2","affected_versions_present":true,"cve_id":"CVE-2026-46426","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46426","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T18:02:00.561Z","patch_url":"","primary_source":"","published":"2026-05-27T17:04:42.080Z"},{"affected":"< 3.38.3","affected_versions_present":true,"cve_id":"CVE-2026-46427","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46427","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T15:05:53.244Z","patch_url":"","primary_source":"","published":"2026-05-27T17:03:10.588Z"},{"affected":"< 3.39.0","affected_versions_present":true,"cve_id":"CVE-2026-48128","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48128","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T18:31:10.697Z","patch_url":"","primary_source":"","published":"2026-05-27T17:01:03.500Z"},{"affected":"< 3.39.0","affected_versions_present":true,"cve_id":"CVE-2026-48146","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48146","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T14:09:35.958Z","patch_url":"","primary_source":"","published":"2026-05-27T17:00:25.739Z"},{"affected":"< 3.39.0","affected_versions_present":true,"cve_id":"CVE-2026-48149","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48149","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T15:01:48.845Z","patch_url":"","primary_source":"","published":"2026-05-27T16:59:31.077Z"},{"affected":"< 3.39.0","affected_versions_present":true,"cve_id":"CVE-2026-48150","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48150","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T17:57:41.445Z","patch_url":"","primary_source":"","published":"2026-05-27T16:58:18.979Z"},{"affected":"< 3.39.0","affected_versions_present":true,"cve_id":"CVE-2026-48151","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48151","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T14:12:26.911Z","patch_url":"","primary_source":"","published":"2026-05-27T16:57:36.447Z"},{"affected":"< 3.39.0","affected_versions_present":true,"cve_id":"CVE-2026-48152","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48152","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T18:41:12.772Z","patch_url":"","primary_source":"","published":"2026-05-27T16:56:46.710Z"},{"affected":"< 3.39.0","affected_versions_present":true,"cve_id":"CVE-2026-48153","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48153","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T18:02:47.454Z","patch_url":"","primary_source":"","published":"2026-05-27T16:52:42.535Z"},{"affected":"< 3.35.10","affected_versions_present":true,"cve_id":"CVE-2026-45061","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45061","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T14:58:59.523Z","patch_url":"","primary_source":"","published":"2026-05-27T16:50:57.549Z"},{"affected":"< 3.35.10","affected_versions_present":true,"cve_id":"CVE-2026-42239","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42239","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-07T19:39:45.605Z","patch_url":"https://github.com/Budibase/budibase/releases/tag/3.35.10","primary_source":"","published":"2026-05-07T18:49:59.180Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Budibase"}}
