CVE-2026-28359Disclosure(nocodb / nocodb)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Editor role can inject arbitrary HTML into Rich Text cells by bypassing the TipTap editor and sending raw HTML via the API. This issue has been patched in version 0.301.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nocodb

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-02); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
nocodb

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-02: 3Mentions · 2026-05-02: 1Technical Details · 2026-03-02: 303-0205-02
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-023
Disclosure3
2026-05-021
General1
Full discourse4 posts
  • ~lyn@lynettdoteth
    General

    @tiredhungryangr One? CVE-2026-2796, CVE-2026-24881, CVE-2026-24882, CVE-2025-32988, CVE-2025-32989, CVE-2025-64175, CVE-2026-25242, CVE-2026-28357, CVE-2026-28359, CVE-2026-26216, CVE-2026-26217, CVE-2026-25946, CVE-2026-32110, CVE-2026-30930, CVE-2026-30928, CVE-2026-32596...

    Post summary

    The tweet merely enumerates a series of CVE identifiers without supplying any evidence of PoC, exploitation activity, patches, technical details, or debunking.

    10000932
    825 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28359 Authenticated HTML Injection in NocoDB Rich Text Cells Before 0.301.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28359

    Post summary

    A new authenticated HTML injection vulnerability (CVE-2026-28359) affecting NocoDB Rich Text Cells before version 0.301.3 has been disclosed, with no PoC, exploit, or patch details provided.

    0000049
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28359 NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Editor role can inject arbitrary HTML into Rich Text c… https://www.cve.org/CVERecord?id=CVE-2026-28359 ----- Traducción: CVE-2026-28359 Noc… http://infoflow.cloud`

    Post summary

    CVE-2026-28359 exposes NocoDB to arbitrary HTML injection by authenticated editors, potentially enabling XSS attacks. The post provides a brief technical description but no PoC, exploit code, or patch information.

    0000030
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28359 NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Editor role can inject arbitrary HTML into Rich Text c… https://www.cve.org/CVERecord?id=CVE-2026-28359

    Post summary

    The CVE describes an authenticated HTML injection vulnerability in NocoDB prior to v0.301.3, allowing Editor role users to inject arbitrary HTML into Rich Text fields.

    00000193
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnocodbnocodb---

Explore more