CVE-2026-91928
- EPSS 0.17%
- Veröffentlicht 23.09.2026 09:37:49
- Zuletzt bearbeitet 30.09.2026 16:12:41
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issu...
CVE-2026-91852
- EPSS 0.21%
- Veröffentlicht 23.09.2026 09:29:11
- Zuletzt bearbeitet 30.09.2026 16:13:54
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issu...
CVE-2026-91999
- EPSS 0.17%
- Veröffentlicht 23.09.2026 09:23:22
- Zuletzt bearbeitet 30.09.2026 16:11:12
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issu...
CVE-2026-92001
- EPSS 0.17%
- Veröffentlicht 23.09.2026 09:20:52
- Zuletzt bearbeitet 30.09.2026 15:59:43
Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issu...
CVE-2026-73192
- EPSS 0.17%
- Veröffentlicht 23.09.2026 09:09:43
- Zuletzt bearbeitet 30.09.2026 16:14:33
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected cross-site s...
CVE-2017-15717
- EPSS 2.91%
- Veröffentlicht 10.01.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:04
A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affect...