Appwrite is a backend-as-a-service platform and development framework that, despite a narrow product scope, serves as critical infrastructure for application developers building and deploying services at scale. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; recurring weaknesses center on server-side request forgery, path traversal, cross-site scripting, prototype pollution, and hard-coded credentials—flaws endemic to web frameworks and API layers that expose both the platform itself and downstream applications built upon it. Defenders should monitor this vendor's advisories closely and prioritize patching in development pipelines and deployed instances; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Appwrite over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27159HIGH Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network re | Mar 31, 2023 | 7.5 | 58 | NO | YES |
CVE-2021-23682CRITICAL This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUr | Feb 16, 2022 | 9.8 | 32 | NO | NO |
CVE-2024-1063HIGH Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an incomplete fix of CVE-2023-27159.
| Jan 30, 2024 | 7.5 | 21 | NO | NO |
CVE-2022-2925MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository appwrite/appwrite prior to 1.0.0-RC1. | Sep 9, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-25377HIGH The ACME-challenge endpoint in Appwrite 0.5.0 through 0.12.x before 0.12.2 allows remote attackers to read arbitrary local files via ../ directory traversal. In order to be vulnera | Feb 22, 2024 | 7.5 | 20 | NO | NO |
CVE-2023-50974MEDIUM In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user | Jan 9, 2024 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Appwrite.
Media articles that mention a CVE ID that affects a product developed by Appwrite — matched by CVE ID, not by vendor name.