subratadeypappu

2 exploits Active since Jan 2026
CVE-2026-7299 WRITEUP MEDIUM WRITEUP
Appsmith < 2.1 - XSS
Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource.
CVSS 6.3
CVE-2026-22794 WRITEUP CRITICAL WRITEUP
Appsmith < 1.93 - Origin Validation Error in Email Link Generation
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / email verification links in emails can be generated pointing to the attacker’s domain, causing authentication tokens to be exposed and potentially leading to account takeover. This vulnerability is fixed in 1.93.
CVSS 9.6