Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CVE-2026-7299
Vulnerability Description
Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
Appsmith 安全漏洞
Vulnerability Description
Appsmith是Appsmith开源的一个用于构建、部署和维护内部应用程序的开源平台。 Appsmith存在安全漏洞,该漏洞源于SQL查询编辑器的自动完成功能未能清理数据库对象名称,可能导致经过身份验证的开发人员注入持久XSS。
CVSS Information
N/A
Vulnerability Type
N/A