CVE Browser

CVE-2026-82875 MEDIUM

ToolJet before v3.16.208 Authorization Bypass via organizationId

CVSS 5.1 EPSS 0.22% Aug 31, 2026
CVE-2026-82874 CRITICAL

ToolJet before v3.16.208 Cross-Tenant Authorization Bypass via tooljet-db

CVSS 9.4 EPSS 0.44% Aug 31, 2026
CVE-2026-82873 MEDIUM

ToolJet through 3.0.0-ee-beta.2 Cross-workspace Schema Disclosure via Export

CVSS 5.3 EPSS 0.30% Aug 31, 2026
CVE-2026-82872 HIGH

ToolJet before v3.16.208 Cross-Workspace Authorization Bypass

CVSS 7.1 EPSS 0.51% Aug 31, 2026
CVE-2026-82871 HIGH

ToolJet before v3.16.208 Cross-Organization Data Read via Database Routes

CVSS 8.2 EPSS 0.41% Aug 31, 2026
CVE-2026-82870 HIGH

ToolJet before v3.16.208 Cross-Tenant Database Manipulation

CVSS 7.0 EPSS 0.43% Aug 31, 2026
CVE-2026-82869 HIGH

ToolJet Database before v3.16.44 Privilege Escalation via join_tables

CVSS 8.2 EPSS 0.41% Aug 31, 2026
CVE-2026-73068 MEDIUM

ToolJet: Cross-tenant Broken Access Control in ToolJet Database (tooljet-db): any authenticated user can read and write another organization's tables

CVSS 5.9 EPSS 0.27% Aug 11, 2026
CVE-2026-54344 HIGH

ToolJet GitHub Actions comment body shell injection exposes deployment secrets

CVSS 8.8 EPSS 0.36% Jul 8, 2026
CVE-2026-55411 MEDIUM

ToolJet: Cross-tenant credential decryption (IDOR) in POST /api/data-sources/decrypt — any authenticated user can decrypt any organization's data-source secrets

CVSS 6.8 EPSS 0.20% Jun 25, 2026
CVE-2026-55412 HIGH

ToolJet Cloud - SSRF to Azure Cloud Infrastructure Compromise

CVSS 8.3 EPSS 0.32% Jun 25, 2026
CVE-2026-55413 CRITICAL

ToolJet - Marketplace Plugin Poisoning Enables Instance-Wide Remote Code Execution

CVSS 9.4 EPSS 0.40% Jun 25, 2026
CVE-2022-27979 MEDIUM

A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the…

CVSS 5.4 EPSS 0.47% Apr 26, 2023
CVE-2022-27978 HIGH

Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.

CVSS 7.5 EPSS 1.04% Apr 26, 2023
CVE-2022-4111 MEDIUM

Improper Validation of Specified Quantity in Input in tooljet/tooljet

CVSS 6.5 EPSS 0.80% Nov 22, 2022
npm
CVE-2022-3422 HIGH

Improper Privilege Management in tooljet/tooljet

CVSS 7.5 EPSS 0.99% Oct 7, 2022
CVE-2022-3348 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor in tooljet/tooljet

CVSS 4.9 EPSS 1.04% Sep 28, 2022
CVE-2022-3019 HIGH

Improper Access Control in tooljet/tooljet

CVSS 8.8 EPSS 0.93% Aug 29, 2022
CVE-2022-2631 HIGH

Improper Access Control in tooljet/tooljet

CVSS 8.8 EPSS 1.16% Aug 2, 2022
CVE-2022-2037 HIGH

Excessive Attack Surface in tooljet/tooljet

CVSS 8.0 EPSS 1.14% Jun 9, 2022
CVE-2022-23068 MEDIUM

ToolJet - HTML Injection in Invite New User

CVSS 5.4 EPSS 0.61% May 18, 2022
CVE-2022-23067 HIGH

ToolJet - Token Leakage via Referer Header

CVSS 8.8 EPSS 1.31% May 18, 2022

Showing 1 to 22 CVEs · page 1