Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Appsmith CRITICAL 9.9
CVE-2026-55454

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has n…

Fix: 2.1+
Fix from $2,300 2026-06-24
Appsmith CRITICAL 9.1
CVE-2026-55455

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (…

Fix: 2.1+
Fix from $2,300 2026-06-24
Appsmith HIGH 7.2
CVE-2026-50189

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interfa…

Fix: 2.1+
Fix from $1,950 2026-06-24
Appsmith MEDIUM 5.4
CVE-2026-7299

Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an auth…

Fix: 1.99+
Fix from $1,600 2026-06-02
Appsmith MEDIUM 5.3
CVE-2026-34411

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoi…

Fix: 1.98+
Fix from $1,600 2026-03-27
Appsmith CRITICAL 9.0
CVE-2026-30862

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table …

Fix: 1.96+
Fix from $2,300 2026-03-10
Appsmith CRITICAL 9.8
CVE-2026-24042

Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthentica…

Fix: after 1.94
Fix from $2,300 2026-01-22
Appsmith HIGH 8.8
CVE-2026-22794

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request header…

Fix: 1.93+
Fix from $1,950 2026-01-12
Appsmith MEDIUM 6.5
CVE-2024-55965

An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (spe…

Fix: 1.51+
Fix from $1,600 2025-03-26
Appsmith CRITICAL 9.8
CVE-2024-55964EPSS 6%

An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command executio…

Fix: 1.52+
Fix from $2,300 2025-03-26
Appsmith MEDIUM 6.5
CVE-2024-55963EPSS 28%

An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, caus…

Fix: 1.51+
Fix from $1,600 2025-03-26
Appsmith MEDIUM 6.5
CVE-2024-51408

AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credent…

Fix: 1.46+
Fix from $1,600 2024-11-04
Appsmith MEDIUM 6.5
CVE-2022-4096

Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.

Fix: 1.8.2+
Fix from $1,600 2022-11-21
Appsmith HIGH 8.8
CVE-2022-38298

Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests t…

Patch available
Fix from $1,950 2022-09-12
Appsmith HIGH 8.9
CVE-2022-39824

Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the curr…

Fix: after 1.7.14
Fix from $1,950 2022-09-05