Appsmith

Appsmith

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.25%
  • Veröffentlicht 24.06.2026 22:16:47
  • Zuletzt bearbeitet 29.06.2026 16:06:39

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accepts attacker-controlled smtpHost and smtpPort values and establishes a raw JavaMail TCP connection withou...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 24.06.2026 21:38:07
  • Zuletzt bearbeitet 26.06.2026 19:50:41

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by default — is bound on 0.0.0.0:2019 inside the container. While this listener is n...

  • EPSS 0.22%
  • Veröffentlicht 24.06.2026 21:36:21
  • Zuletzt bearbeitet 26.06.2026 19:50:00

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the REST API and GraphQL datasource plugins) validates hosts against an exact-match string de...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 24.06.2026 21:35:00
  • Zuletzt bearbeitet 26.06.2026 19:50:17

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interface on port 9001, reachable from outside the container via a Caddy reverse-proxy route at /supervisor/...

Medienbericht Exploit
  • EPSS 0.34%
  • Veröffentlicht 02.06.2026 14:07:52
  • Zuletzt bearbeitet 22.07.2026 19:10:00

Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrar...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 27.03.2026 16:24:16
  • Zuletzt bearbeitet 14.07.2026 19:17:01

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1/tenants/current to retrieve configuration metadata...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 09.03.2026 22:26:11
  • Zuletzt bearbeitet 13.03.2026 15:34:16

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2). The root cause is a lack of HTML sanitization in the React component renderin...

  • EPSS 0.58%
  • Veröffentlicht 22.01.2026 03:52:54
  • Zuletzt bearbeitet 17.02.2026 17:50:44

Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthenticated users to execute unpublished (edit-mode) actions by sending viewMode=false (or omitting it) to PO...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 12.01.2026 21:54:52
  • Zuletzt bearbeitet 21.01.2026 19:14:17

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / ...

  • EPSS 6.27%
  • Veröffentlicht 26.03.2025 20:15:21
  • Zuletzt bearbeitet 01.04.2025 16:34:34

An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacker must be able to access Appsmith, login to it, cr...