Sploitus

CVE-2026-48149

No indexed exploits for CVE-2026-48149 yet

Budibase is an open-source low-code platform. Prior to 3.39.0, the Budibase Text component renders markdown by assigning marked.parse(markdown) straight to innerHTML with no sanitizer (packages/bbui/src/Markdown/MarkdownViewer.svelte:22). Any column a builder binds to a Text component in Markdown mode is a stored-XSS sink writable by every BASIC app user with WRITE on the underlying table. This vulnerability is fixed in 3.39.0.

Affected products
Budibase
Fix
Available
CVSS 3.1
8.1 HIGH
EPSS
0.2% (13th percentile)
Weakness
CWE-79
NVD status
Deferred
Published
2026-05-27
CVE-2026-48149 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-48149 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-48149 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.