Stored XSS Vulnerability in NocoDB Software for Spreadsheet Database Management
CVE-2026-28397

5.3MEDIUM

Key Information:

Vendor

Nocodb

Status
Vendor
CVE Published:
2 March 2026

What is CVE-2026-28397?

NocoDB is a versatile software solution that transforms your databases into spreadsheet-like interfaces. However, prior to version 0.301.3, it had a vulnerability that allowed comments to be rendered via v-html without proper sanitization. This flaw could potentially enable attackers to exploit stored XSS attacks, compromising the security of applications utilizing NocoDB. The vulnerability has been addressed in version 0.301.3, enhancing the overall security of the platform.

Affected Version(s)

nocodb < 0.301.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.