VCL
Apache · 3 CVEs
CVE-2024-53679
HIGH
Apache VCL: XSS vulnerability in User Lookup impacting user privileges
Mar 25, 2025
CVE-2024-53678
MEDIUM
Apache VCL: SQL injection vulnerability in New Block Allocation form
Mar 25, 2025
CVE-2018-11772
HIGH
Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previ…
Jul 29, 2019
CVE-2018-11774
HIGH
Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts.…
Jul 29, 2019
CVE-2018-11773
CRITICAL
Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. T…
Jul 29, 2019
CVE-2013-0267
HIGH
The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 a…
Feb 21, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-53679 | Apache VCL: XSS vulnerability in User Lookup impacting user privileges | HIGH | 0.53% | Mar 25, 2025 |
| CVE-2024-53678 | Apache VCL: SQL injection vulnerability in New Block Allocation form | MEDIUM | 0.61% | Mar 25, 2025 |
| CVE-2018-11772 | Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. Th… | HIGH | 1.36% | Jul 29, 2019 |
| CVE-2018-11774 | Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL state… | HIGH | 1.36% | Jul 29, 2019 |
| CVE-2018-11773 | Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument… | CRITICAL | 2.10% | Jul 29, 2019 |
| CVE-2013-0267 | The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nod… | HIGH | 3.68% | Feb 21, 2018 |
Showing 1 to 3 of 3 CVEs