ToolJet records
11 published records for vendor tooljet.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 18.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-284 Improper Access Control2
- CWE-269 Improper Privilege Management1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-755 Improper Handling of Exceptional Conditions1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-23067No exploit | ToolJet - Token Leakage via Referer Headertooljet · tooljet · CWE-200 | High8.8 | — | 1.3% | May 18, 2022 |
35Monitor | CVE-2022-2631No exploit | Improper Access Control in tooljet/tooljettooljet · tooljet · CWE-284 | High8.8 | — | 1.2% | Aug 2, 2022 |
35Monitor | CVE-2022-3019No exploit | Improper Access Control in tooljet/tooljettooljet · tooljet · CWE-284 | High8.8 | — | 0.9% | Aug 29, 2022 |
35Monitor | CVE-2026-54344No exploit | ToolJet GitHub Actions comment body shell injection exposes deployment secretstooljet · tooljet · CWE-78 | High8.8 | — | 0.4% | Jul 8, 2026 |
32Monitor | CVE-2022-2037No exploit | Excessive Attack Surface in tooljet/tooljettooljet · tooljet · CWE-1125 | High8.0 | — | 1.1% | Jun 9, 2022 |
30Monitor | CVE-2022-27978No exploit | Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP requestooljet · tooljet · CWE-755 | High7.5 | — | 1.0% | Apr 26, 2023 |
30Monitor | CVE-2022-3422No exploit | Improper Privilege Management in tooljet/tooljettooljet · tooljet · CWE-269 | High7.5 | — | 0.9% | Oct 7, 2022 |
26Monitor | CVE-2022-4111No exploit | Improper Validation of Specified Quantity in Input in tooljet/tooljettooljet · tooljet · CWE-1284 | Medium6.5 | — | 0.8% | Nov 21, 2022 |
21Monitor | CVE-2022-23068No exploit | ToolJet - HTML Injection in Invite New Usertooljet · tooljet · CWE-74 | Medium5.4 | — | 0.6% | May 18, 2022 |
21Monitor | CVE-2022-27979No exploit | A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloadtooljet · tooljet · CWE-79 | Medium5.4 | — | 0.5% | Apr 26, 2023 |
19Monitor | CVE-2022-3348No exploit | Exposure of Sensitive Information to an Unauthorized Actor in tooljet/tooljettooljet · tooljet · CWE-200 | Medium4.9 | — | 1.0% | Sep 28, 2022 |
- CVE-2022-2306735Monitor
ToolJet - Token Leakage via Referer Header
HighCVSS 8.8No exploitEPSS 1%tooljet · tooljetMay 18, 2022
- CVE-2022-263135Monitor
Improper Access Control in tooljet/tooljet
HighCVSS 8.8No exploitEPSS 1%tooljet · tooljetAug 2, 2022
- CVE-2022-301935Monitor
Improper Access Control in tooljet/tooljet
HighCVSS 8.8No exploitEPSS 1%tooljet · tooljetAug 29, 2022
- CVE-2026-5434435Monitor
ToolJet GitHub Actions comment body shell injection exposes deployment secrets
HighCVSS 8.8No exploitEPSS 0%tooljet · tooljetJul 8, 2026
- CVE-2022-203732Monitor
Excessive Attack Surface in tooljet/tooljet
HighCVSS 8.0No exploitEPSS 1%tooljet · tooljetJun 9, 2022
- CVE-2022-2797830Monitor
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP reques
HighCVSS 7.5No exploitEPSS 1%tooljet · tooljetApr 26, 2023
- CVE-2022-342230Monitor
Improper Privilege Management in tooljet/tooljet
HighCVSS 7.5No exploitEPSS 1%tooljet · tooljetOct 7, 2022
- CVE-2022-411126Monitor
Improper Validation of Specified Quantity in Input in tooljet/tooljet
MediumCVSS 6.5No exploitEPSS 1%tooljet · tooljetNov 21, 2022
- CVE-2022-2306821Monitor
ToolJet - HTML Injection in Invite New User
MediumCVSS 5.4No exploitEPSS 1%tooljet · tooljetMay 18, 2022
- CVE-2022-2797921Monitor
A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload
MediumCVSS 5.4No exploitEPSS 0%tooljet · tooljetApr 26, 2023
- CVE-2022-334819Monitor
Exposure of Sensitive Information to an Unauthorized Actor in tooljet/tooljet
MediumCVSS 4.9No exploitEPSS 1%tooljet · tooljetSep 28, 2022