Mel O'Hagan
5 exploits
Active since Mar 2026
Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist
CVSS 9.6
Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write
CVSS 8.7
Budibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step
CVSS 9.0
Budibase: Stored XSS via unsanitized entity names rendered with {@html} in Builder Command Palette
CVSS 8.7
Budibase <=3.23.22 - Command Injection
CVSS 7.2