Apache answer
This hub aggregates every CVE we track for Apache answer, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
18
CVEs tracked
1
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM13LOW2HIGH2CRITICAL1
Monthly trend
0
2
1
0
1
0
0
0
0
1
0
0
0
0
0
0
0
0
0
1
0
0
0
7
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache answer.
- CVE-2026-25700Apache Answer: AdminToken not invalidated after admin deactivation7.2
- CVE-2026-34905Apache Answer: Unlisted Questions Accessible via Direct API Access6.5
- CVE-2026-34033Apache Answer: HTML Content Injection in Email5.4
- CVE-2026-34031Apache Answer: The custom avatar was not properly validated6.5
- CVE-2026-33582Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error6.5
- CVE-2026-25699Apache Answer: Authorization Bypass in Timeline API6.1
- CVE-2026-25688Apache Answer: XSS in AI Answer Rendering6.1
- CVE-2026-24735Apache Answer: Revision API Improper Access Control leads to Information Disclosure7.5
- CVE-2025-29868Apache Answer: Using externally referenced images can leak user privacy.6.5
- CVE-2024-45719Apache Answer: Predictable Authorization Token Using UUIDv12.6
- CVE-2024-40761Apache Answer: Avatar URL leaked user email addresses5.3
- CVE-2024-41888Apache Answer: The link for resetting user password is not Single-Use5.3
- CVE-2024-41890Apache Answer: The link to reset the user's password will remain valid after sending a new link5.3
- CVE-2024-29217Apache Answer: XSS vulnerability when changing personal website4.6
- CVE-2024-22393Apache Answer: Pixel Flood Attack by uploading the large pixel file9.1
Product normalization is registry-driven with AI assist and human review. How it works