Vulnerability index

Browse CVEs

166 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Airflow MEDIUM 5.4
CVE-2024-32077

Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users a…

Patch available
Fix from $1,600 2024-05-14
Zeppelin MEDIUM 6.1
CVE-2024-31868

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal us…

Fix: 0.11.1+
Fix from $1,600 2024-04-09
Archiva MEDIUM 5.4
CVE-2024-27140

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva…

Mitigation only
Fix from $1,600 2024-03-01
Ambari MEDIUM 6.1
CVE-2023-50378

Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8    Impact : As it will be stored XSS, Could be exploited …

Fix: 2.7.8+
Fix from $1,600 2024-03-01
Answer MEDIUM 5.4
CVE-2024-23349

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer:…

Fix: after 1.2.1
Fix from $1,600 2024-02-22
Superset MEDIUM 5.4
CVE-2023-49657

A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on…

Fix: 3.0.3+
Fix from $1,600 2024-01-23
Airflow MEDIUM 5.4
CVE-2023-47265

Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript…

Fix: after 2.7.3
Fix from $1,600 2023-12-21
Nifi MEDIUM 5.4
CVE-2023-49145

Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable …

Fix: 1.24.0+
Fix from $1,600 2023-11-27
Superset MEDIUM 5.4
CVE-2023-43701

Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious actor to store malicious code int…

Fix: 2.1.2+
Fix from $1,600 2023-11-27
Brpc MEDIUM 6.1
CVE-2023-45757

Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz page. An attacker that can sen…

Fix: 1.6.1+
Fix from $1,600 2023-10-16
Roller MEDIUM 5.4
CVE-2023-37581

Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all …

Fix: 6.1.2+
Fix from $1,600 2023-08-06
Felix Health Check Webconsole Plugin MEDIUM 6.1
CVE-2023-38435

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole…

Fix: 2.1.0+
Fix from $1,600 2023-07-25
Jspwiki MEDIUM 6.1
CVE-2022-46907

A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execut…

Fix: 2.12.0+
Fix from $1,600 2023-05-25
Airflow MEDIUM 5.4
CVE-2023-29247

Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.

Fix: 2.6.0+
Fix from $1,600 2023-05-08
Apache Sling Engine CRITICAL 9.0
CVE-2022-45064

The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting is…

Fix: 2.14.0+
Fix from $2,300 2023-04-13
Archiva MEDIUM 5.4
CVE-2023-28158

Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users…

Fix: 2.2.10+
Fix from $1,600 2023-03-29
Sling Cms MEDIUM 6.1
CVE-2023-22849

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and pri…

Fix: 1.1.6+
Fix from $1,600 2023-02-04
Superset MEDIUM 5.4
CVE-2022-43717

Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by…

Fix: after 1.5.2
Fix from $1,600 2023-01-16
Superset MEDIUM 5.4
CVE-2022-43718

Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with databas…

Fix: after 1.5.2
Fix from $1,600 2023-01-16
Sling Cms MEDIUM 5.4
CVE-2022-46769

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and pri…

Fix: 1.1.4+
Fix from $1,600 2023-01-09
Traffic Server MEDIUM 6.1
CVE-2022-40743

Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting an…

Fix: after 9.1.3
Fix from $1,600 2022-12-19
Zeppelin MEDIUM 5.4
CVE-2022-46870

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to ex…

Fix: 0.8.2+
Fix from $1,600 2022-12-16
Sling Cms MEDIUM 5.4
CVE-2022-43670

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and pri…

Fix: after 1.1.0
Fix from $1,600 2022-11-02
Airflow MEDIUM 6.1
CVE-2022-43982

In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument.

Fix: 2.4.2+
Fix from $1,600 2022-11-02
Geode MEDIUM 5.4
CVE-2022-34870

Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region …

Fix: after 1.15.0
Fix from $1,600 2022-10-25
Isis MEDIUM 6.1
CVE-2022-42466

Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be render…

Fix: 2.0.0+
Fix from $1,600 2022-10-19
Ofbiz MEDIUM 5.4
CVE-2022-25370

Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.…

Fix: 18.12.06+
Fix from $1,600 2022-09-02
Artemis MEDIUM 6.1
CVE-2022-35278

In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by u…

Fix: 2.24.0+
Fix from $1,600 2022-08-23
Jspwiki MEDIUM 6.1
CVE-2022-27166EPSS 85%

A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow …

Fix: 2.11.3+
Fix from $1,600 2022-08-04
Jspwiki MEDIUM 6.1
CVE-2022-28730EPSS 85%

A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javasc…

Fix: 2.11.3+
Fix from $1,600 2022-08-04