Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 04 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:* |
Tue, 02 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Tue, 02 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Appsmith
Appsmith appsmith |
|
| Vendors & Products |
Appsmith
Appsmith appsmith |
Tue, 02 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 02 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspace members when they interact with the same datasource. | |
| Title | CVE-2026-7299 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-06-02T18:17:31.812Z
Reserved: 2026-04-28T11:32:21.296Z
Link: CVE-2026-7299
Updated: 2026-06-02T15:23:03.693Z
Status : Analyzed
Published: 2026-06-02T16:16:45.557
Modified: 2026-06-04T17:41:57.573
Link: CVE-2026-7299
No data.
OpenCVE Enrichment
Updated: 2026-06-02T17:15:19Z