Appsmith kayıtları
appsmith üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %5,6
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %44,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-280 Improper Handling of Insufficient Permissions or Privileges1
- CWE-284 Improper Access Control1
- CWE-306 Missing Authentication for Critical Function1
- CWE-346 Origin Validation Error1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2024-55964Silahlaştırılmış | An issue was discovered in Appsmith before 1.52.appsmith · appsmith · CWE-94 | Kritik9,8 | — | %6,8 | 26 Mar 2025 |
39İzleyin | CVE-2026-24042İstismar yok | Appsmith public apps can execute unpublished actions (viewMode confusion)appsmith · appsmith · CWE-862 | Kritik9,8 | — | %0,7 | 22 Oca 2026 |
39İzleyin | CVE-2026-55454İstismar yok | Appsmith: Caddy admin API exposed without authenticationappsmith · appsmith · CWE-749 | Kritik9,9 | — | %0,6 | 24 Haz 2026 |
36İzleyin | CVE-2026-30862Kavram kanıtı | Critical Stored XSS & Privilege Escalation in Appsmithappsmith · appsmith · CWE-79 | Kritik9,0 | — | %0,4 | 10 Mar 2026 |
35İzleyin | CVE-2024-55963Kavram kanıtı | An issue was discovered in Appsmith before 1.51.appsmith · appsmith · CWE-284 | Orta6,5 | — | %30,7 | 26 Mar 2025 |
35İzleyin | CVE-2022-39824İstismar yok | Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server viaappsmith · appsmith · CWE-79 | Yüksek8,9 | — | %1,1 | 4 Eyl 2022 |
35İzleyin | CVE-2022-38298İstismar yok | Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming rappsmith · appsmith · CWE-918 | Yüksek8,8 | — | %0,7 | 12 Eyl 2022 |
35İzleyin | CVE-2026-50189İstismar yok | Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Routeappsmith · appsmith · CWE-183 | Yüksek8,9 | — | %0,5 | 24 Haz 2026 |
35İzleyin | CVE-2026-22794Kavram kanıtı | Account Takeover Vulnerability in Appsmithappsmith · appsmith · CWE-346 | Yüksek8,8 | — | %0,4 | 12 Oca 2026 |
27İzleyin | CVE-2026-34411İstismar yok | Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIsappsmith · appsmith · CWE-306 | Orta6,9 | — | %0,4 | 27 Mar 2026 |
26İzleyin | CVE-2022-4096Kavram kanıtı | Server-Side Request Forgery (SSRF) in appsmithorg/appsmithappsmith · appsmith · CWE-918 | Orta6,5 | — | %1,6 | 21 Kas 2022 |
26İzleyin | CVE-2024-51408İstismar yok | AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadatappsmith · appsmith · CWE-918 | Orta6,5 | — | %0,5 | 4 Kas 2024 |
26İzleyin | CVE-2024-55965İstismar yok | An issue was discovered in Appsmith before 1.51.appsmith · appsmith · CWE-863 | Orta6,5 | — | %0,4 | 26 Mar 2025 |
21İzleyin | CVE-2026-7299Kavram kanıtı | Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowinappsmith · appsmith · CWE-79 | Orta5,4 | — | %0,4 | 2 Haz 2026 |
21İzleyin | CVE-2026-55455İstismar yok | Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylistappsmith · appsmith · CWE-918 | Orta5,3 | — | %0,4 | 24 Haz 2026 |
20İzleyin | CVE-2026-49979İstismar yok | Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filterappsmith · appsmith · CWE-209 | Orta5,1 | — | %0,4 | 24 Haz 2026 |
19İzleyin | CVE-2024-55604İstismar yok | Appsmith's Broken Access Control Allows Viewer Role User to Query Datasourcesappsmith · appsmith · CWE-280 | Orta4,8 | — | %0,2 | 25 Mar 2025 |
17İzleyin | CVE-2022-38299İstismar yok | An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpoappsmith · appsmith | Orta4,3 | — | %0,6 | 12 Eyl 2022 |
- CVE-2024-5596441Planlayın
An issue was discovered in Appsmith before 1.52.
KritikCVSS 9,8SilahlaştırılmışEPSS %7appsmith · appsmith26 Mar 2025
- CVE-2026-2404239İzleyin
Appsmith public apps can execute unpublished actions (viewMode confusion)
KritikCVSS 9,8İstismar yokEPSS %1appsmith · appsmith22 Oca 2026
- CVE-2026-5545439İzleyin
Appsmith: Caddy admin API exposed without authentication
KritikCVSS 9,9İstismar yokEPSS %1appsmith · appsmith24 Haz 2026
- CVE-2026-3086236İzleyin
Critical Stored XSS & Privilege Escalation in Appsmith
KritikCVSS 9,0Kavram kanıtıEPSS %0appsmith · appsmith10 Mar 2026
- CVE-2024-5596335İzleyin
An issue was discovered in Appsmith before 1.51.
OrtaCVSS 6,5Kavram kanıtıEPSS %31appsmith · appsmith26 Mar 2025
- CVE-2022-3982435İzleyin
Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via
YüksekCVSS 8,9İstismar yokEPSS %1appsmith · appsmith4 Eyl 2022
- CVE-2022-3829835İzleyin
Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming r
YüksekCVSS 8,8İstismar yokEPSS %1appsmith · appsmith12 Eyl 2022
- CVE-2026-5018935İzleyin
Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route
YüksekCVSS 8,9İstismar yokEPSS %0appsmith · appsmith24 Haz 2026
- CVE-2026-2279435İzleyin
Account Takeover Vulnerability in Appsmith
YüksekCVSS 8,8Kavram kanıtıEPSS %0appsmith · appsmith12 Oca 2026
- CVE-2026-3441127İzleyin
Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs
OrtaCVSS 6,9İstismar yokEPSS %0appsmith · appsmith27 Mar 2026
- CVE-2022-409626İzleyin
Server-Side Request Forgery (SSRF) in appsmithorg/appsmith
OrtaCVSS 6,5Kavram kanıtıEPSS %2appsmith · appsmith21 Kas 2022
- CVE-2024-5140826İzleyin
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadat
OrtaCVSS 6,5İstismar yokEPSS %0appsmith · appsmith4 Kas 2024
- CVE-2024-5596526İzleyin
An issue was discovered in Appsmith before 1.51.
OrtaCVSS 6,5İstismar yokEPSS %0appsmith · appsmith26 Mar 2025
- CVE-2026-729921İzleyin
Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowin
OrtaCVSS 5,4Kavram kanıtıEPSS %0appsmith · appsmith2 Haz 2026
- CVE-2026-5545521İzleyin
Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylist
OrtaCVSS 5,3İstismar yokEPSS %0appsmith · appsmith24 Haz 2026
- CVE-2026-4997920İzleyin
Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter
OrtaCVSS 5,1İstismar yokEPSS %0appsmith · appsmith24 Haz 2026
- CVE-2024-5560419İzleyin
Appsmith's Broken Access Control Allows Viewer Role User to Query Datasources
OrtaCVSS 4,8İstismar yokEPSS %0appsmith · appsmith25 Mar 2025
- CVE-2022-3829917İzleyin
An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpo
OrtaCVSS 4,3İstismar yokEPSS %1appsmith · appsmith12 Eyl 2022