Перейти к содержимому
Noroxi

Записи Appsmith

18 опубликованных записей вендора appsmith.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 5,6 %
Pre-auth RCE
1
С записью об исправлении
44,4 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

18 записей
  • CVE-2024-55964
    41В плане

    An issue was discovered in Appsmith before 1.52.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 7 %

    appsmith · appsmith26 мар. 2025 г.

  • CVE-2026-24042
    39Наблюдать

    Appsmith public apps can execute unpublished actions (viewMode confusion)

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    appsmith · appsmith22 янв. 2026 г.

  • CVE-2026-55454
    39Наблюдать

    Appsmith: Caddy admin API exposed without authentication

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    appsmith · appsmith24 июн. 2026 г.

  • CVE-2026-30862
    36Наблюдать

    Critical Stored XSS & Privilege Escalation in Appsmith

    КритическаяCVSS 9,0Proof of conceptEPSS 0 %

    appsmith · appsmith10 мар. 2026 г.

  • CVE-2024-55963
    35Наблюдать

    An issue was discovered in Appsmith before 1.51.

    СредняяCVSS 6,5Proof of conceptEPSS 31 %

    appsmith · appsmith26 мар. 2025 г.

  • CVE-2022-39824
    35Наблюдать

    Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via

    ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %

    appsmith · appsmith4 сент. 2022 г.

  • CVE-2022-38298
    35Наблюдать

    Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming r

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    appsmith · appsmith12 сент. 2022 г.

  • CVE-2026-50189
    35Наблюдать

    Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route

    ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %

    appsmith · appsmith24 июн. 2026 г.

  • CVE-2026-22794
    35Наблюдать

    Account Takeover Vulnerability in Appsmith

    ВысокаяCVSS 8,8Proof of conceptEPSS 0 %

    appsmith · appsmith12 янв. 2026 г.

  • CVE-2026-34411
    27Наблюдать

    Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    appsmith · appsmith27 мар. 2026 г.

  • CVE-2022-4096
    26Наблюдать

    Server-Side Request Forgery (SSRF) in appsmithorg/appsmith

    СредняяCVSS 6,5Proof of conceptEPSS 2 %

    appsmith · appsmith21 нояб. 2022 г.

  • CVE-2024-51408
    26Наблюдать

    AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadat

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    appsmith · appsmith4 нояб. 2024 г.

  • CVE-2024-55965
    26Наблюдать

    An issue was discovered in Appsmith before 1.51.

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    appsmith · appsmith26 мар. 2025 г.

  • CVE-2026-7299
    21Наблюдать

    Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowin

    СредняяCVSS 5,4Proof of conceptEPSS 0 %

    appsmith · appsmith2 июн. 2026 г.

  • CVE-2026-55455
    21Наблюдать

    Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylist

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    appsmith · appsmith24 июн. 2026 г.

  • CVE-2026-49979
    20Наблюдать

    Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    appsmith · appsmith24 июн. 2026 г.

  • CVE-2024-55604
    19Наблюдать

    Appsmith's Broken Access Control Allows Viewer Role User to Query Datasources

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    appsmith · appsmith25 мар. 2025 г.

  • CVE-2022-38299
    17Наблюдать

    An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpo

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    appsmith · appsmith12 сент. 2022 г.