Known CVE
NocoDB < 0.258.0 - Reflected XSS in Password Reset
NocoDB versions before 0.258.0 contain a reflected cross-site scripting caused by insecure use of '\u003C%-' in resetPassword.ts, letting attackers execute malicious scripts in victims' browsers, exploit requires sending crafted requests to /api/v1/db/auth/password/reset/:tokenId.
CVE-2025-27506
Medium2025CVSS 5.4CWE-79
cve2025 · nocodb · xss · reflected · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website