Записи Appsmith
18 опубликованных записей вендора appsmith.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 5,6 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 44,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-280 Improper Handling of Insufficient Permissions or Privileges1
- CWE-284 Improper Access Control1
- CWE-306 Missing Authentication for Critical Function1
- CWE-346 Origin Validation Error1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2024-55964Готовый эксплойт | An issue was discovered in Appsmith before 1.52.appsmith · appsmith · CWE-94 | Критическая9,8 | — | 6,8 % | 26 мар. 2025 г. |
39Наблюдать | CVE-2026-24042Эксплойта нет | Appsmith public apps can execute unpublished actions (viewMode confusion)appsmith · appsmith · CWE-862 | Критическая9,8 | — | 0,7 % | 22 янв. 2026 г. |
39Наблюдать | CVE-2026-55454Эксплойта нет | Appsmith: Caddy admin API exposed without authenticationappsmith · appsmith · CWE-749 | Критическая9,9 | — | 0,6 % | 24 июн. 2026 г. |
36Наблюдать | CVE-2026-30862Proof of concept | Critical Stored XSS & Privilege Escalation in Appsmithappsmith · appsmith · CWE-79 | Критическая9,0 | — | 0,4 % | 10 мар. 2026 г. |
35Наблюдать | CVE-2024-55963Proof of concept | An issue was discovered in Appsmith before 1.51.appsmith · appsmith · CWE-284 | Средняя6,5 | — | 30,7 % | 26 мар. 2025 г. |
35Наблюдать | CVE-2022-39824Эксплойта нет | Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server viaappsmith · appsmith · CWE-79 | Высокая8,9 | — | 1,1 % | 4 сент. 2022 г. |
35Наблюдать | CVE-2022-38298Эксплойта нет | Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming rappsmith · appsmith · CWE-918 | Высокая8,8 | — | 0,7 % | 12 сент. 2022 г. |
35Наблюдать | CVE-2026-50189Эксплойта нет | Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Routeappsmith · appsmith · CWE-183 | Высокая8,9 | — | 0,5 % | 24 июн. 2026 г. |
35Наблюдать | CVE-2026-22794Proof of concept | Account Takeover Vulnerability in Appsmithappsmith · appsmith · CWE-346 | Высокая8,8 | — | 0,4 % | 12 янв. 2026 г. |
27Наблюдать | CVE-2026-34411Эксплойта нет | Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIsappsmith · appsmith · CWE-306 | Средняя6,9 | — | 0,4 % | 27 мар. 2026 г. |
26Наблюдать | CVE-2022-4096Proof of concept | Server-Side Request Forgery (SSRF) in appsmithorg/appsmithappsmith · appsmith · CWE-918 | Средняя6,5 | — | 1,6 % | 21 нояб. 2022 г. |
26Наблюдать | CVE-2024-51408Эксплойта нет | AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadatappsmith · appsmith · CWE-918 | Средняя6,5 | — | 0,5 % | 4 нояб. 2024 г. |
26Наблюдать | CVE-2024-55965Эксплойта нет | An issue was discovered in Appsmith before 1.51.appsmith · appsmith · CWE-863 | Средняя6,5 | — | 0,4 % | 26 мар. 2025 г. |
21Наблюдать | CVE-2026-7299Proof of concept | Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowinappsmith · appsmith · CWE-79 | Средняя5,4 | — | 0,4 % | 2 июн. 2026 г. |
21Наблюдать | CVE-2026-55455Эксплойта нет | Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylistappsmith · appsmith · CWE-918 | Средняя5,3 | — | 0,4 % | 24 июн. 2026 г. |
20Наблюдать | CVE-2026-49979Эксплойта нет | Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filterappsmith · appsmith · CWE-209 | Средняя5,1 | — | 0,4 % | 24 июн. 2026 г. |
19Наблюдать | CVE-2024-55604Эксплойта нет | Appsmith's Broken Access Control Allows Viewer Role User to Query Datasourcesappsmith · appsmith · CWE-280 | Средняя4,8 | — | 0,2 % | 25 мар. 2025 г. |
17Наблюдать | CVE-2022-38299Эксплойта нет | An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpoappsmith · appsmith | Средняя4,3 | — | 0,6 % | 12 сент. 2022 г. |
- CVE-2024-5596441В плане
An issue was discovered in Appsmith before 1.52.
КритическаяCVSS 9,8Готовый эксплойтEPSS 7 %appsmith · appsmith26 мар. 2025 г.
- CVE-2026-2404239Наблюдать
Appsmith public apps can execute unpublished actions (viewMode confusion)
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %appsmith · appsmith22 янв. 2026 г.
- CVE-2026-5545439Наблюдать
Appsmith: Caddy admin API exposed without authentication
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %appsmith · appsmith24 июн. 2026 г.
- CVE-2026-3086236Наблюдать
Critical Stored XSS & Privilege Escalation in Appsmith
КритическаяCVSS 9,0Proof of conceptEPSS 0 %appsmith · appsmith10 мар. 2026 г.
- CVE-2024-5596335Наблюдать
An issue was discovered in Appsmith before 1.51.
СредняяCVSS 6,5Proof of conceptEPSS 31 %appsmith · appsmith26 мар. 2025 г.
- CVE-2022-3982435Наблюдать
Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via
ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %appsmith · appsmith4 сент. 2022 г.
- CVE-2022-3829835Наблюдать
Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming r
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %appsmith · appsmith12 сент. 2022 г.
- CVE-2026-5018935Наблюдать
Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route
ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %appsmith · appsmith24 июн. 2026 г.
- CVE-2026-2279435Наблюдать
Account Takeover Vulnerability in Appsmith
ВысокаяCVSS 8,8Proof of conceptEPSS 0 %appsmith · appsmith12 янв. 2026 г.
- CVE-2026-3441127Наблюдать
Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs
СредняяCVSS 6,9Эксплойта нетEPSS 0 %appsmith · appsmith27 мар. 2026 г.
- CVE-2022-409626Наблюдать
Server-Side Request Forgery (SSRF) in appsmithorg/appsmith
СредняяCVSS 6,5Proof of conceptEPSS 2 %appsmith · appsmith21 нояб. 2022 г.
- CVE-2024-5140826Наблюдать
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadat
СредняяCVSS 6,5Эксплойта нетEPSS 0 %appsmith · appsmith4 нояб. 2024 г.
- CVE-2024-5596526Наблюдать
An issue was discovered in Appsmith before 1.51.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %appsmith · appsmith26 мар. 2025 г.
- CVE-2026-729921Наблюдать
Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowin
СредняяCVSS 5,4Proof of conceptEPSS 0 %appsmith · appsmith2 июн. 2026 г.
- CVE-2026-5545521Наблюдать
Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylist
СредняяCVSS 5,3Эксплойта нетEPSS 0 %appsmith · appsmith24 июн. 2026 г.
- CVE-2026-4997920Наблюдать
Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter
СредняяCVSS 5,1Эксплойта нетEPSS 0 %appsmith · appsmith24 июн. 2026 г.
- CVE-2024-5560419Наблюдать
Appsmith's Broken Access Control Allows Viewer Role User to Query Datasources
СредняяCVSS 4,8Эксплойта нетEPSS 0 %appsmith · appsmith25 мар. 2025 г.
- CVE-2022-3829917Наблюдать
An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpo
СредняяCVSS 4,3Эксплойта нетEPSS 1 %appsmith · appsmith12 сент. 2022 г.