Vulnerability index

Browse CVEs

166 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Wicket MEDIUM 6.1
CVE-2026-66390

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicke…

Fix: 10.10.0+
Fix from $1,600 2026-07-27
Activemq MEDIUM 6.1
CVE-2026-52760

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. …

Fix: 5.19.8 / 6.2.7+
Fix from $1,600 2026-06-30
Answer MEDIUM 5.4
CVE-2026-34033

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: thro…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
HTTP Server MEDIUM 6.1
CVE-2026-29170

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing F…

Fix: 2.4.68+
Fix from $1,600 2026-06-08
Activemq MEDIUM 6.1
CVE-2026-42253

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The Mess…

Fix: 5.19.7 / 6.2.6+
Fix from $1,600 2026-06-01
Echarts MEDIUM 6.1
CVE-2026-45249

A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache EChart…

Fix: 6.1.0+
Fix from $1,600 2026-05-25
Ofbiz MEDIUM 6.1
CVE-2026-31379

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 6.1
CVE-2026-31906

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz:…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Wicket MEDIUM 6.1
CVE-2026-42509

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicke…

Fix: 10.9.0+
Fix from $1,600 2026-05-06
Activemq MEDIUM 6.5
CVE-2026-41043

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticate…

Fix: 5.19.6 / 6.2.5+
Fix from $1,600 2026-04-24
Storm MEDIUM 5.4
CVE-2026-35565

Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI …

Fix: 2.8.6+
Fix from $1,600 2026-04-13
Syncope MEDIUM 6.8
CVE-2026-23794

Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Sync…

Fix: 3.0.16 / 4.0.4+
Fix from $1,600 2026-02-03
Ofbiz MEDIUM 6.5
CVE-2025-61623

Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to…

Fix: 24.09.03+
Fix from $1,600 2025-11-12
Geode MEDIUM 6.1
CVE-2024-44088

Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a…

Fix: 1.15.2+
Fix from $1,600 2025-10-14
Zeppelin MEDIUM 6.1
CVE-2024-41177

Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recomme…

Fix: 0.12.0+
Fix from $1,600 2025-08-03
Jspwiki MEDIUM 6.1
CVE-2025-24854

A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute …

Fix: 2.12.3+
Fix from $1,600 2025-07-31
Jspwiki HIGH 7.5
CVE-2025-24853

A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the v…

Fix: 2.12.3+
Fix from $1,950 2025-07-31
Ofbiz MEDIUM 6.1
CVE-2025-30676EPSS 65%

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before…

Fix: 18.12.19+
Fix from $1,600 2025-04-01
Vcl MEDIUM 5.4
CVE-2024-53679

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with…

Fix: 2.5.2+
Fix from $1,600 2025-03-25
Oozie MEDIUM 5.4
CVE-2025-26796

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. …

Mitigation only
Fix from $1,600 2025-03-22
Druid MEDIUM 5.4
CVE-2025-27888

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…

Fix: 31.0.2+
Fix from $1,600 2025-03-20
Felix Http Webconsole Plugin MEDIUM 5.6
CVE-2025-27867

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issu…

Fix: 1.2.2+
Fix from $1,600 2025-03-12
Felix Webconsole MEDIUM 6.1
CVE-2025-25247

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Ap…

Fix: 4.9.10 / 5.0.10+
Fix from $1,600 2025-02-10
Syncope MEDIUM 6.1
CVE-2024-45031

When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored X…

Fix: 3.0.9+
Fix from $1,600 2024-10-24
Airflow MEDIUM 6.1
CVE-2024-41937

Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting atta…

Fix: 2.10.0+
Fix from $1,600 2024-08-21
Roller MEDIUM 5.4
CVE-2024-25090

Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of …

Fix: 6.1.3+
Fix from $1,600 2024-07-26
Syncope MEDIUM 5.4
CVE-2024-38503

When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The…

Fix: 3.0.8+
Fix from $1,600 2024-07-22
Airflow MEDIUM 5.4
CVE-2024-39863

Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider…

Fix: 2.9.3+
Fix from $1,600 2024-07-17
Nifi MEDIUM 5.4
CVE-2024-37389EPSS 24%

Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable…

Fix: 1.27.0+
Fix from $1,600 2024-07-08
Jspwiki MEDIUM 6.1
CVE-2024-27136EPSS 59%

XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive infor…

Fix: 2.12.2+
Fix from $1,600 2024-06-24