appium records
7 published records for vendor appium.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 85.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2023-2479Proof of concept | OS Command Injection in appium/appium-desktopappium · appium-desktop · CWE-78 | Critical9.8 | — | 22.0% | May 2, 2023 |
40Plan | CVE-2026-58192No exploit | Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-pluginappium · appium\/storage-plugin · CWE-22 | Critical10.0 | — | 0.6% | Jul 8, 2026 |
32Monitor | CVE-2016-10557No exploit | appium-chromedriver is a Node.js wrapper around Chromedriver.appium · appium-chromedriver · CWE-311 | High8.1 | — | 1.1% | May 31, 2018 |
32Monitor | CVE-2026-43910No exploit | Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutorappium · java-client · CWE-441 | High8.2 | — | 0.4% | Jul 28, 2026 |
32Monitor | CVE-2026-58500No exploit | MCP Appium: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)appium · appium-mcp · CWE-79 | High8.2 | — | 0.4% | Jul 13, 2026 |
26Monitor | CVE-2026-30973No exploit | Zip Slip arbitrary file write in @appium/support ZIP extractionappium · appium\/support · CWE-22 | Medium6.5 | — | 0.4% | Mar 10, 2026 |
24Monitor | CVE-2026-58191Proof of concept | Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routesappium · appium\/base-driver · CWE-79 | Medium6.1 | — | 0.6% | Jul 8, 2026 |
- CVE-2023-247946Plan
OS Command Injection in appium/appium-desktop
CriticalCVSS 9.8Proof of conceptEPSS 22%appium · appium-desktopMay 2, 2023
- CVE-2026-5819240Plan
Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin
CriticalCVSS 10.0No exploitEPSS 1%appium · appium\/storage-pluginJul 8, 2026
- CVE-2016-1055732Monitor
appium-chromedriver is a Node.js wrapper around Chromedriver.
HighCVSS 8.1No exploitEPSS 1%appium · appium-chromedriverMay 31, 2018
- CVE-2026-4391032Monitor
Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
HighCVSS 8.2No exploitEPSS 0%appium · java-clientJul 28, 2026
- CVE-2026-5850032Monitor
MCP Appium: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)
HighCVSS 8.2No exploitEPSS 0%appium · appium-mcpJul 13, 2026
- CVE-2026-3097326Monitor
Zip Slip arbitrary file write in @appium/support ZIP extraction
MediumCVSS 6.5No exploitEPSS 0%appium · appium\/supportMar 10, 2026
- CVE-2026-5819124Monitor
Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
MediumCVSS 6.1Proof of conceptEPSS 1%appium · appium\/base-driverJul 8, 2026