apache-software-foundation
Latest CVEs
The 15 most recently published vulnerabilities affecting apache-software-foundation.
- CVE-2026-80190Apache Allura: Stored XSS via code repositories6.1
- CVE-2026-81270Apache Allura: Information exposure via search7.5
- CVE-2026-80180Apache Allura: Stored XSS via markdown HTML processing6.1
- CVE-2026-32773Apache Spark: XSS Vulnerability in Spark Web 3.5.46.1
- CVE-2026-76986Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue6.1
- CVE-2026-76985Apache Wicket: XSS in Palette via getAdditionalAttributes5.4
- CVE-2026-76983Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel5.4
- CVE-2026-76984Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute5.4
- CVE-2026-76982Apache Wicket: XSS in Button via its model object5.4
- CVE-2026-75802Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel5.4
- CVE-2026-71378Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener4.6
- CVE-2026-71257Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed7.5
- CVE-2026-70449Apache Wicket: Path traversal in resource style/variation/locale5.3
- CVE-2026-58301Apache Shiro: Server-side POST request may be steered to an alternate host6.5
- CVE-2026-74848Apache APISIX: Cross-user response poisoning in serverless plugins7.5