| CERT Vulnerability Notes Database |
| 1 |
VU#265691 - Appsmiths SQL Query autocomplete renderer contains a cross site scripting vulnerability |
https://www.kb.cert.org/vuls/id/265691
|
| GitHub |
| 2 |
fix(security): block SSRF via send-test-email SMTP host validation (GHSA-vvxf-f8q9-86gh) by subrata71 Pull Request #41666 appsmithorg/appsmith GitHub |
https://github.com/appsmithorg/appsmith/pull/41666
|
| 3 |
GitHub - Stuub/Appsmith-1.98-Stored-XSS-Exploit: Automating the exploitation of CVE-2026-7299 - Stored XSS via Database Table/Column Names in SQL Autocomplete within Appsmith =>1.99. Initial discovery 30/03/26 GitHub |
https://github.com/Stuub/Appsmith-1.98-Stored-XSS-Exploit
|
| 4 |
SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter Advisory appsmithorg/appsmith GitHub |
https://github.com/appsmithorg/appsmith/security/advisories/GHSA-vvxf-f8q9-86gh
|