Apache sling
This hub aggregates every CVE we track for Apache sling, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
1
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM4HIGH2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 7 most recently published vulnerabilities affecting Apache sling.
- CVE-2023-25621Apache Sling does not allow to handle i18n content in a secure way6.5
- CVE-2022-32549log injection in Sling logging5.3
- CVE-2017-15717A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass a...6.1
- CVE-2012-3353The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing ...7.5
- CVE-2017-15700A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send ove...8.8
- CVE-2016-6798In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts wh...9.8
- CVE-2016-5394In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough and for some input patterns allows script tags t...6.1
Product normalization is registry-driven with AI assist and human review. How it works