Skip to content
Noroxi

Appsmith records

18 published records for vendor appsmith.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 5.6%
Pre-auth RCE
1
With a fix record
44.4%
Median publish → KEV
No record has entered KEV

All records

18 records
  • An issue was discovered in Appsmith before 1.52.

    CriticalCVSS 9.8WeaponizedEPSS 7%

    appsmith · appsmithMar 26, 2025

  • Appsmith public apps can execute unpublished actions (viewMode confusion)

    CriticalCVSS 9.8No exploitEPSS 1%

    appsmith · appsmithJan 22, 2026

  • Appsmith: Caddy admin API exposed without authentication

    CriticalCVSS 9.9No exploitEPSS 1%

    appsmith · appsmithJun 24, 2026

  • Critical Stored XSS & Privilege Escalation in Appsmith

    CriticalCVSS 9.0Proof of conceptEPSS 0%

    appsmith · appsmithMar 10, 2026

  • An issue was discovered in Appsmith before 1.51.

    MediumCVSS 6.5Proof of conceptEPSS 31%

    appsmith · appsmithMar 26, 2025

  • Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via

    HighCVSS 8.9No exploitEPSS 1%

    appsmith · appsmithSep 4, 2022

  • Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming r

    HighCVSS 8.8No exploitEPSS 1%

    appsmith · appsmithSep 12, 2022

  • Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route

    HighCVSS 8.9No exploitEPSS 0%

    appsmith · appsmithJun 24, 2026

  • Account Takeover Vulnerability in Appsmith

    HighCVSS 8.8Proof of conceptEPSS 0%

    appsmith · appsmithJan 12, 2026

  • Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs

    MediumCVSS 6.9No exploitEPSS 0%

    appsmith · appsmithMar 27, 2026

  • CVE-2022-4096
    26Monitor

    Server-Side Request Forgery (SSRF) in appsmithorg/appsmith

    MediumCVSS 6.5Proof of conceptEPSS 2%

    appsmith · appsmithNov 21, 2022

  • AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadat

    MediumCVSS 6.5No exploitEPSS 0%

    appsmith · appsmithNov 4, 2024

  • An issue was discovered in Appsmith before 1.51.

    MediumCVSS 6.5No exploitEPSS 0%

    appsmith · appsmithMar 26, 2025

  • CVE-2026-7299
    21Monitor

    Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowin

    MediumCVSS 5.4Proof of conceptEPSS 0%

    appsmith · appsmithJun 2, 2026

  • Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylist

    MediumCVSS 5.3No exploitEPSS 0%

    appsmith · appsmithJun 24, 2026

  • Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter

    MediumCVSS 5.1No exploitEPSS 0%

    appsmith · appsmithJun 24, 2026

  • Appsmith's Broken Access Control Allows Viewer Role User to Query Datasources

    MediumCVSS 4.8No exploitEPSS 0%

    appsmith · appsmithMar 25, 2025

  • An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpo

    MediumCVSS 4.3No exploitEPSS 1%

    appsmith · appsmithSep 12, 2022