CVE-2026-60053
- EPSS 0.27%
- Veröffentlicht 05.08.2026 15:13:10
- Zuletzt bearbeitet 07.08.2026 13:08:20
Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or de...
CVE-2026-60023
- EPSS 0.17%
- Veröffentlicht 05.08.2026 15:12:08
- Zuletzt bearbeitet 06.08.2026 18:40:35
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be retrieved by unauthorized users through the single-answer read path when...
CVE-2026-50749
- EPSS 0.16%
- Veröffentlicht 05.08.2026 15:11:05
- Zuletzt bearbeitet 06.08.2026 18:38:07
Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject ...
CVE-2026-48912
- EPSS 0.18%
- Veröffentlicht 05.08.2026 15:10:08
- Zuletzt bearbeitet 06.08.2026 18:38:14
Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their...
CVE-2026-48911
- EPSS 0.17%
- Veröffentlicht 05.08.2026 15:09:14
- Zuletzt bearbeitet 06.08.2026 18:38:18
Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arb...
CVE-2026-48834
- EPSS 0.18%
- Veröffentlicht 05.08.2026 15:07:35
- Zuletzt bearbeitet 06.08.2026 18:38:23
Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that trigger...
CVE-2026-25700
- EPSS 0.45%
- Veröffentlicht 10.06.2026 14:57:00
- Zuletzt bearbeitet 12.06.2026 00:50:20
Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, o...
CVE-2026-34905
- EPSS 0.33%
- Veröffentlicht 09.06.2026 07:35:56
- Zuletzt bearbeitet 23.07.2026 08:10:00
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenti...
CVE-2026-34033
- EPSS 0.37%
- Veröffentlicht 09.06.2026 07:35:16
- Zuletzt bearbeitet 23.07.2026 08:10:00
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied content was included in notification emails without proper escaping, allowi...
CVE-2026-34031
- EPSS 0.4%
- Veröffentlicht 09.06.2026 07:34:38
- Zuletzt bearbeitet 23.07.2026 08:10:00
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded a...