Where
-Infinity
0

Vendor Risk Score

See how appsmith compares to other vendors in security performance

View Risk Score →

AppSmith AppsmithAppsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter

Risk 23
Severity
5.1
First published (updated )

AppSmith AppsmithAppsmith: Caddy admin API exposed without authentication

Risk 82
Severity
9.9
First published (updated )

AppSmith AppsmithAppsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylist

Risk 66
Severity
5.3
First published (updated )

AppSmith AppsmithAppsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route

Risk 70
Severity
8.9
First published (updated )

AppSmith AppsmithXSS

Risk 43
Severity
6.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

AppSmith Appsmithappsmithorg appsmith Dashboard WebClientUtils.java computeDisallowedHosts server-side request forgery

Risk 37
Severity
5.5
EPSS
0.05%
First published (updated )

AppSmith AppsmithAppsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs

Risk 23
Severity
6.9
EPSS
0.06%
First published (updated )

AppSmith AppsmithCritical Stored XSS & Privilege Escalation in Appsmith

Risk 55
Severity
9.1
EPSS
0.05%
First published (updated )

AppSmith AppsmithAppsmith public apps can execute unpublished actions (viewMode confusion)

Risk 61
Severity
9.8
EPSS
0.07%
First published (updated )

npm/appsmithAccount Takeover Vulnerability in Appsmith

Risk 58
Severity
9.7
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

AppSmith AppsmithAn issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissi…

Risk 65
Severity
6.5
First published (updated )

AppSmith AppsmithCode Injection

Risk 86
Severity
9.8
First published (updated )

AppSmith AppsmithAn issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have acce…

Risk 38
Severity
6.5
First published (updated )

CVE-2024-55963: Unauthenticated RCE in Default-Install of Appsmith

First published (updated )
Social
reddit

AppSmith AppsmithAppsmith's Broken Access Control Allows Viewer Role User to Query Datasources

Risk 24
Severity
4.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

AppSmith AppsmithSSRF

Risk 73
Severity
8.5
First published (updated )

AppSmith AppsmithServer-Side Request Forgery (SSRF) in appsmithorg/appsmith

Risk 79
Severity
6.5
First published (updated )

AppSmith AppsmithAn issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed host…

Risk 22
Severity
4.3
First published (updated )

AppSmith AppsmithSSRF

Risk 79
Severity
8.8
First published (updated )

AppSmith AppsmithXSS

Risk 70
Severity
8.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203