Apache Answer

Apache · 24 CVEs

CVE-2026-60053
CRITICAL

Apache Answer: Residual Administrative API Key Access After Role or Account Revocation

Aug 5, 2026

CVE-2026-60023
HIGH

Apache Answer: Unauthorized disclosure of deleted or pending answer content

Aug 5, 2026

CVE-2026-50749
MEDIUM

Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions

Aug 5, 2026

CVE-2026-48912
MEDIUM

Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded…

Aug 5, 2026

CVE-2026-48911
HIGH

Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow

Aug 5, 2026

CVE-2026-48834
HIGH

Apache Answer: Denial of service via crafted Accept-Language header parsing

Aug 5, 2026

CVE-2026-25700
HIGH

Apache Answer: AdminToken not invalidated after admin deactivation

Jun 10, 2026

CVE-2026-34905
MEDIUM

Apache Answer: Unlisted Questions Accessible via Direct API Access

Jun 9, 2026

CVE-2026-34033
MEDIUM

Apache Answer: HTML Content Injection in Email

Jun 9, 2026

CVE-2026-34031
MEDIUM

Apache Answer: The custom avatar was not properly validated

Jun 9, 2026

CVE-2026-33582
MEDIUM

Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error

Jun 9, 2026

CVE-2026-25699
MEDIUM

Apache Answer: Authorization Bypass in Timeline API

Jun 9, 2026

CVE-2026-25688
MEDIUM

Apache Answer: XSS in AI Answer Rendering

Jun 9, 2026

CVE-2026-24735
MEDIUM

Apache Answer: Revision API Improper Access Control leads to Information Disclosure

Feb 4, 2026

CVE-2025-29868
LOW

Apache Answer: Using externally referenced images can leak user privacy.

Apr 1, 2025

CVE-2024-45719
LOW

Apache Answer: Predictable Authorization Token Using UUIDv1

Nov 22, 2024

CVE-2024-40761
MEDIUM

Apache Answer: Avatar URL leaked user email addresses

Sep 25, 2024

CVE-2024-41888
MEDIUM

Apache Answer: The link for resetting user password is not Single-Use

Aug 9, 2024

CVE-2024-41890
MEDIUM

Apache Answer: The link to reset the user's password will remain valid after sending a new link

Aug 9, 2024

CVE-2024-29217
MEDIUM

Apache Answer: XSS vulnerability when changing personal website

Apr 21, 2024

CVE-2024-22393
HIGH

Apache Answer: Pixel Flood Attack by uploading the large pixel file

Feb 22, 2024

CVE-2024-23349
MEDIUM

Apache Answer: XSS vulnerability when submitting summary

Feb 22, 2024

CVE-2024-26578
MEDIUM

Apache Answer: Repeated submission at registration created duplicate users with the same name

Feb 22, 2024

CVE-2023-49619
LOW

Apache Answer: Repeated submissions using scripts resulted in an abnormal number of collections for questions.

Jan 10, 2024

Showing 1 to 24 of 24 CVEs