Skip to content
Noroxi

ToolJet records

11 published records for vendor tooljet.

All records

11 records
  • ToolJet - Token Leakage via Referer Header

    HighCVSS 8.8No exploitEPSS 1%

    tooljet · tooljetMay 18, 2022

  • CVE-2022-2631
    35Monitor

    Improper Access Control in tooljet/tooljet

    HighCVSS 8.8No exploitEPSS 1%

    tooljet · tooljetAug 2, 2022

  • CVE-2022-3019
    35Monitor

    Improper Access Control in tooljet/tooljet

    HighCVSS 8.8No exploitEPSS 1%

    tooljet · tooljetAug 29, 2022

  • ToolJet GitHub Actions comment body shell injection exposes deployment secrets

    HighCVSS 8.8No exploitEPSS 0%

    tooljet · tooljetJul 8, 2026

  • CVE-2022-2037
    32Monitor

    Excessive Attack Surface in tooljet/tooljet

    HighCVSS 8.0No exploitEPSS 1%

    tooljet · tooljetJun 9, 2022

  • Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP reques

    HighCVSS 7.5No exploitEPSS 1%

    tooljet · tooljetApr 26, 2023

  • CVE-2022-3422
    30Monitor

    Improper Privilege Management in tooljet/tooljet

    HighCVSS 7.5No exploitEPSS 1%

    tooljet · tooljetOct 7, 2022

  • CVE-2022-4111
    26Monitor

    Improper Validation of Specified Quantity in Input in tooljet/tooljet

    MediumCVSS 6.5No exploitEPSS 1%

    tooljet · tooljetNov 21, 2022

  • ToolJet - HTML Injection in Invite New User

    MediumCVSS 5.4No exploitEPSS 1%

    tooljet · tooljetMay 18, 2022

  • A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload

    MediumCVSS 5.4No exploitEPSS 0%

    tooljet · tooljetApr 26, 2023

  • CVE-2022-3348
    19Monitor

    Exposure of Sensitive Information to an Unauthorized Actor in tooljet/tooljet

    MediumCVSS 4.9No exploitEPSS 1%

    tooljet · tooljetSep 28, 2022