İçeriğe atla
Noroxi

Appsmith kayıtları

appsmith üreticisine ait 18 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %5,6
Pre-auth RCE
1
Düzeltme kaydı olan
%44,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

18 kayıt
  • CVE-2024-55964
    41Planlayın

    An issue was discovered in Appsmith before 1.52.

    KritikCVSS 9,8SilahlaştırılmışEPSS %7

    appsmith · appsmith26 Mar 2025

  • CVE-2026-24042
    39İzleyin

    Appsmith public apps can execute unpublished actions (viewMode confusion)

    KritikCVSS 9,8İstismar yokEPSS %1

    appsmith · appsmith22 Oca 2026

  • CVE-2026-55454
    39İzleyin

    Appsmith: Caddy admin API exposed without authentication

    KritikCVSS 9,9İstismar yokEPSS %1

    appsmith · appsmith24 Haz 2026

  • CVE-2026-30862
    36İzleyin

    Critical Stored XSS & Privilege Escalation in Appsmith

    KritikCVSS 9,0Kavram kanıtıEPSS %0

    appsmith · appsmith10 Mar 2026

  • CVE-2024-55963
    35İzleyin

    An issue was discovered in Appsmith before 1.51.

    OrtaCVSS 6,5Kavram kanıtıEPSS %31

    appsmith · appsmith26 Mar 2025

  • CVE-2022-39824
    35İzleyin

    Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via

    YüksekCVSS 8,9İstismar yokEPSS %1

    appsmith · appsmith4 Eyl 2022

  • CVE-2022-38298
    35İzleyin

    Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming r

    YüksekCVSS 8,8İstismar yokEPSS %1

    appsmith · appsmith12 Eyl 2022

  • CVE-2026-50189
    35İzleyin

    Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route

    YüksekCVSS 8,9İstismar yokEPSS %0

    appsmith · appsmith24 Haz 2026

  • CVE-2026-22794
    35İzleyin

    Account Takeover Vulnerability in Appsmith

    YüksekCVSS 8,8Kavram kanıtıEPSS %0

    appsmith · appsmith12 Oca 2026

  • CVE-2026-34411
    27İzleyin

    Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs

    OrtaCVSS 6,9İstismar yokEPSS %0

    appsmith · appsmith27 Mar 2026

  • CVE-2022-4096
    26İzleyin

    Server-Side Request Forgery (SSRF) in appsmithorg/appsmith

    OrtaCVSS 6,5Kavram kanıtıEPSS %2

    appsmith · appsmith21 Kas 2022

  • CVE-2024-51408
    26İzleyin

    AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadat

    OrtaCVSS 6,5İstismar yokEPSS %0

    appsmith · appsmith4 Kas 2024

  • CVE-2024-55965
    26İzleyin

    An issue was discovered in Appsmith before 1.51.

    OrtaCVSS 6,5İstismar yokEPSS %0

    appsmith · appsmith26 Mar 2025

  • CVE-2026-7299
    21İzleyin

    Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowin

    OrtaCVSS 5,4Kavram kanıtıEPSS %0

    appsmith · appsmith2 Haz 2026

  • CVE-2026-55455
    21İzleyin

    Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylist

    OrtaCVSS 5,3İstismar yokEPSS %0

    appsmith · appsmith24 Haz 2026

  • CVE-2026-49979
    20İzleyin

    Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter

    OrtaCVSS 5,1İstismar yokEPSS %0

    appsmith · appsmith24 Haz 2026

  • CVE-2024-55604
    19İzleyin

    Appsmith's Broken Access Control Allows Viewer Role User to Query Datasources

    OrtaCVSS 4,8İstismar yokEPSS %0

    appsmith · appsmith25 Mar 2025

  • CVE-2022-38299
    17İzleyin

    An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP internal metadata endpo

    OrtaCVSS 4,3İstismar yokEPSS %1

    appsmith · appsmith12 Eyl 2022