Syncope
This hub aggregates every CVE we track for Syncope, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
24
CVEs tracked
7
Critical
7
High
0
In CISA KEV
Severity distribution
MEDIUM10HIGH7CRITICAL7
Monthly trend
0
1
0
0
0
0
0
0
0
0
0
0
0
1
1
0
0
2
0
0
2
0
6
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Syncope.
- CVE-2026-62418Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check8.1
- CVE-2026-62183Apache Syncope: User self-service privilege escalation9.8
- CVE-2026-57308Apache Syncope: SQL injection vulnerability in Audit Events search9.8
- CVE-2026-53421Apache Syncope: Remote Code Execution via Scripted Connector9.8
- CVE-2026-53405Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask9.8
- CVE-2026-63071Apache Syncope: RCE via Groovy Sandbox bypass9.8
- CVE-2026-42797Apache Syncope: JexlContextBuilder Information Disclosure4.9
- CVE-2026-42782Apache Syncope: Post-auth RCE via Groovy static7.2
- CVE-2026-23794Apache Syncope: Reflected XSS on Enduser Login6.8
- CVE-2026-23795Apache Syncope: Console XXE on Keymaster parameters4.9
- CVE-2025-65998Apache Syncope: Default AES key used for internal password encryption7.5
- CVE-2025-57738Apache Syncope: Remote Code Execution by delegated administrators7.2
- CVE-2024-45031Apache Syncope: Stored XSS in Console and Enduser6.1
- CVE-2024-38503Apache Syncope: HTML tags can be injected into Console or Enduser text fields5.4
- CVE-2020-11977In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, inc...7.2
Product normalization is registry-driven with AI assist and human review. How it works