Appsmith records
18 published records for vendor appsmith.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 5.6%
- Pre-auth RCE
- 1
- With a fix record
- 44.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-280 Improper Handling of Insufficient Permissions or Privileges1
- CWE-284 Improper Access Control1
- CWE-306 Missing Authentication for Critical Function1
- CWE-346 Origin Validation Error1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2024-55964Weaponized | An issue was discovered in Appsmith before 1.52.appsmith · appsmith · CWE-94 | Critical9.8 | — | 6.8% | Mar 26, 2025 |
39Monitor | CVE-2026-24042No exploit | Appsmith public apps can execute unpublished actions (viewMode confusion)appsmith · appsmith · CWE-862 | Critical9.8 | — | 0.7% | Jan 22, 2026 |
39Monitor | CVE-2026-55454No exploit | Appsmith: Caddy admin API exposed without authenticationappsmith · appsmith · CWE-749 | Critical9.9 | — | 0.6% | Jun 24, 2026 |
36Monitor | CVE-2026-30862Proof of concept | Critical Stored XSS & Privilege Escalation in Appsmithappsmith · appsmith · CWE-79 | Critical9.0 | — | 0.4% | Mar 10, 2026 |
35Monitor | CVE-2024-55963Proof of concept | An issue was discovered in Appsmith before 1.51.appsmith · appsmith · CWE-284 | Medium6.5 | — | 30.7% | Mar 26, 2025 |
35Monitor | CVE-2022-39824No exploit | Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server viaappsmith · appsmith · CWE-79 | High8.9 | — | 1.1% | Sep 4, 2022 |
35Monitor | CVE-2022-38298No exploit | Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming rappsmith · appsmith · CWE-918 | High8.8 | — | 0.7% | Sep 12, 2022 |
35Monitor | CVE-2026-50189No exploit | Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Routeappsmith · appsmith · CWE-183 | High8.9 | — | 0.5% | Jun 24, 2026 |
35Monitor | CVE-2026-22794Proof of concept | Account Takeover Vulnerability in Appsmithappsmith · appsmith · CWE-346 | High8.8 | — | 0.4% | Jan 12, 2026 |
27Monitor | CVE-2026-34411No exploit | Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIsappsmith · appsmith · CWE-306 | Medium6.9 | — | 0.4% | Mar 27, 2026 |
26Monitor | CVE-2022-4096Proof of concept | Server-Side Request Forgery (SSRF) in appsmithorg/appsmithappsmith · appsmith · CWE-918 | Medium6.5 | — | 1.6% | Nov 21, 2022 |
26Monitor | CVE-2024-51408No exploit | AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadatappsmith · appsmith · CWE-918 | Medium6.5 | — | 0.5% | Nov 4, 2024 |
26Monitor | CVE-2024-55965No exploit | An issue was discovered in Appsmith before 1.51.appsmith · appsmith · CWE-863 | Medium6.5 | — | 0.4% | Mar 26, 2025 |
21Monitor | CVE-2026-7299Proof of concept | Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowinappsmith · appsmith · CWE-79 | Medium5.4 | — | 0.4% | Jun 2, 2026 |
21Monitor | CVE-2026-55455No exploit | Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylistappsmith · appsmith · CWE-918 | Medium5.3 | — | 0.4% | Jun 24, 2026 |
20Monitor | CVE-2026-49979No exploit | Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filterappsmith · appsmith · CWE-209 | Medium5.1 | — | 0.4% | Jun 24, 2026 |
19Monitor | CVE-2024-55604No exploit | Appsmith's Broken Access Control Allows Viewer Role User to Query Datasourcesappsmith · appsmith · CWE-280 | Medium4.8 | — | 0.2% | Mar 25, 2025 |
17Monitor | CVE-2022-38299No exploit | An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpoappsmith · appsmith | Medium4.3 | — | 0.6% | Sep 12, 2022 |
- CVE-2024-5596441Plan
An issue was discovered in Appsmith before 1.52.
CriticalCVSS 9.8WeaponizedEPSS 7%appsmith · appsmithMar 26, 2025
- CVE-2026-2404239Monitor
Appsmith public apps can execute unpublished actions (viewMode confusion)
CriticalCVSS 9.8No exploitEPSS 1%appsmith · appsmithJan 22, 2026
- CVE-2026-5545439Monitor
Appsmith: Caddy admin API exposed without authentication
CriticalCVSS 9.9No exploitEPSS 1%appsmith · appsmithJun 24, 2026
- CVE-2026-3086236Monitor
Critical Stored XSS & Privilege Escalation in Appsmith
CriticalCVSS 9.0Proof of conceptEPSS 0%appsmith · appsmithMar 10, 2026
- CVE-2024-5596335Monitor
An issue was discovered in Appsmith before 1.51.
MediumCVSS 6.5Proof of conceptEPSS 31%appsmith · appsmithMar 26, 2025
- CVE-2022-3982435Monitor
Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via
HighCVSS 8.9No exploitEPSS 1%appsmith · appsmithSep 4, 2022
- CVE-2022-3829835Monitor
Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming r
HighCVSS 8.8No exploitEPSS 1%appsmith · appsmithSep 12, 2022
- CVE-2026-5018935Monitor
Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route
HighCVSS 8.9No exploitEPSS 0%appsmith · appsmithJun 24, 2026
- CVE-2026-2279435Monitor
Account Takeover Vulnerability in Appsmith
HighCVSS 8.8Proof of conceptEPSS 0%appsmith · appsmithJan 12, 2026
- CVE-2026-3441127Monitor
Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs
MediumCVSS 6.9No exploitEPSS 0%appsmith · appsmithMar 27, 2026
- CVE-2022-409626Monitor
Server-Side Request Forgery (SSRF) in appsmithorg/appsmith
MediumCVSS 6.5Proof of conceptEPSS 2%appsmith · appsmithNov 21, 2022
- CVE-2024-5140826Monitor
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadat
MediumCVSS 6.5No exploitEPSS 0%appsmith · appsmithNov 4, 2024
- CVE-2024-5596526Monitor
An issue was discovered in Appsmith before 1.51.
MediumCVSS 6.5No exploitEPSS 0%appsmith · appsmithMar 26, 2025
- CVE-2026-729921Monitor
Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowin
MediumCVSS 5.4Proof of conceptEPSS 0%appsmith · appsmithJun 2, 2026
- CVE-2026-5545521Monitor
Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylist
MediumCVSS 5.3No exploitEPSS 0%appsmith · appsmithJun 24, 2026
- CVE-2026-4997920Monitor
Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter
MediumCVSS 5.1No exploitEPSS 0%appsmith · appsmithJun 24, 2026
- CVE-2024-5560419Monitor
Appsmith's Broken Access Control Allows Viewer Role User to Query Datasources
MediumCVSS 4.8No exploitEPSS 0%appsmith · appsmithMar 25, 2025
- CVE-2022-3829917Monitor
An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpo
MediumCVSS 4.3No exploitEPSS 1%appsmith · appsmithSep 12, 2022