No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 10 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Appsmith
Appsmith appsmith |
|
| Vendors & Products |
Appsmith
Appsmith appsmith |
Mon, 09 Mar 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2). The root cause is a lack of HTML sanitization in the React component rendering pipeline, allowing malicious attributes to be interpolated into the DOM. By leveraging the "Invite Users" feature, an attacker with a regular user account (user@gmail.com) can force a System Administrator to execute a high-privileged API call (/api/v1/admin/env), resulting in a Full Administrative Account Takeover. This vulnerability is fixed in 1.96. | |
| Title | Critical Stored XSS & Privilege Escalation in Appsmith | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-10T14:19:20.885Z
Reserved: 2026-03-05T21:27:35.342Z
Link: CVE-2026-30862
Updated: 2026-03-10T14:19:10.529Z
Status : Received
Published: 2026-03-10T17:40:14.123
Modified: 2026-03-10T18:18:50.547
Link: CVE-2026-30862
No data.
OpenCVE Enrichment
Updated: 2026-03-10T14:06:35Z