Org.apache.sling:org.apache.sling.api
This hub aggregates every CVE we track for Org.apache.sling:org.apache.sling.api, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 3 most recently published vulnerabilities affecting Org.apache.sling:org.apache.sling.api.
- CVE-2022-32549log injection in Sling logging5.3
- CVE-2015-2944Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via th...4.3
- CVE-2013-2254The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that ...5.0
Product normalization is registry-driven with AI assist and human review. How it works