Appsmith is a low-code application development platform that sits centrally in internal application architecture, where a single instance can expose diverse backend systems and data sources to end users. Its vulnerability profile skews toward serious outcomes with an elevated share reaching critical severity, and the vendor's disclosures frequently acquire public exploit code. The recurring weakness classes—cross-site scripting, server-side request forgery, improper access control, code injection, and insufficient privilege handling—reflect the inherent complexity of a platform that bridges user input, code generation, and broad backend connectivity, and these classes have been repeatedly weaponized in similar development and integration tools. Defenders should treat this vendor's security advisories as high-priority for internet-accessible instances and apply patches promptly; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Appsmith over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-55963MEDIUM An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is s | Mar 26, 2025 | 6.5 | 49 | NO | YES |
CVE-2026-55454CRITICAL Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by default — i | Jun 24, 2026 | 9.9 | 41 | NO | NO |
CVE-2024-55964CRITICAL An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker co | Mar 26, 2025 | 9.8 | 41 | NO | YES |
CVE-2026-55455CRITICAL Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the REST API and GraphQ | Jun 24, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-24042CRITICAL Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthenticated users to execute unpublishe | Jan 22, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-22794HIGH Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl wit | Jan 12, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-50189HIGH Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interface on port 9001, reachable from | Jun 24, 2026 | 7.2 | 31 | NO | NO |
CVE-2022-39824HIGH Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the currentItem property of the list wi | Sep 5, 2022 | 8.9 | 29 | NO | NO |
CVE-2026-30862CRITICAL Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2). The roo | Mar 10, 2026 | 9.0 | 28 | NO | NO |
CVE-2022-38298HIGH Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via redirecting incoming requests to the AWS internal metadata end | Sep 12, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Appsmith.
Media articles that mention a CVE ID that affects a product developed by Appsmith — matched by CVE ID, not by vendor name.