Apache Answer
Apache · 24 CVEs
Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
Aug 5, 2026
Apache Answer: Unauthorized disclosure of deleted or pending answer content
Aug 5, 2026
Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
Aug 5, 2026
Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded…
Aug 5, 2026
Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
Aug 5, 2026
Apache Answer: Denial of service via crafted Accept-Language header parsing
Aug 5, 2026
Apache Answer: AdminToken not invalidated after admin deactivation
Jun 10, 2026
Apache Answer: Unlisted Questions Accessible via Direct API Access
Jun 9, 2026
Apache Answer: HTML Content Injection in Email
Jun 9, 2026
Apache Answer: The custom avatar was not properly validated
Jun 9, 2026
Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error
Jun 9, 2026
Apache Answer: Authorization Bypass in Timeline API
Jun 9, 2026
Apache Answer: XSS in AI Answer Rendering
Jun 9, 2026
Apache Answer: Revision API Improper Access Control leads to Information Disclosure
Feb 4, 2026
Apache Answer: Using externally referenced images can leak user privacy.
Apr 1, 2025
Apache Answer: Predictable Authorization Token Using UUIDv1
Nov 22, 2024
Apache Answer: Avatar URL leaked user email addresses
Sep 25, 2024
Apache Answer: The link for resetting user password is not Single-Use
Aug 9, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link
Aug 9, 2024
Apache Answer: XSS vulnerability when changing personal website
Apr 21, 2024
Apache Answer: Pixel Flood Attack by uploading the large pixel file
Feb 22, 2024
Apache Answer: XSS vulnerability when submitting summary
Feb 22, 2024
Apache Answer: Repeated submission at registration created duplicate users with the same name
Feb 22, 2024
Apache Answer: Repeated submissions using scripts resulted in an abnormal number of collections for questions.
Jan 10, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-60053 | Apache Answer: Residual Administrative API Key Access After Role or Account Revocation | CRITICAL | 0.57% | Aug 5, 2026 |
| CVE-2026-60023 | Apache Answer: Unauthorized disclosure of deleted or pending answer content | HIGH | 0.62% | Aug 5, 2026 |
| CVE-2026-50749 | Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions | MEDIUM | 0.47% | Aug 5, 2026 |
| CVE-2026-48912 | Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL | MEDIUM | 0.47% | Aug 5, 2026 |
| CVE-2026-48911 | Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow | HIGH | 0.57% | Aug 5, 2026 |
| CVE-2026-48834 | Apache Answer: Denial of service via crafted Accept-Language header parsing | HIGH | 0.76% | Aug 5, 2026 |
| CVE-2026-25700 | Apache Answer: AdminToken not invalidated after admin deactivation | HIGH | 0.65% | Jun 10, 2026 |
| CVE-2026-34905 | Apache Answer: Unlisted Questions Accessible via Direct API Access | MEDIUM | 0.51% | Jun 9, 2026 |
| CVE-2026-34033 | Apache Answer: HTML Content Injection in Email | MEDIUM | 0.52% | Jun 9, 2026 |
| CVE-2026-34031 | Apache Answer: The custom avatar was not properly validated | MEDIUM | 0.64% | Jun 9, 2026 |
| CVE-2026-33582 | Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error | MEDIUM | 0.65% | Jun 9, 2026 |
| CVE-2026-25699 | Apache Answer: Authorization Bypass in Timeline API | MEDIUM | 0.57% | Jun 9, 2026 |
| CVE-2026-25688 | Apache Answer: XSS in AI Answer Rendering | MEDIUM | 0.57% | Jun 9, 2026 |
| CVE-2026-24735 | Apache Answer: Revision API Improper Access Control leads to Information Disclosure | MEDIUM | 0.69% | Feb 4, 2026 |
| CVE-2025-29868 | Apache Answer: Using externally referenced images can leak user privacy. | LOW | 0.95% | Apr 1, 2025 |
| CVE-2024-45719 | Apache Answer: Predictable Authorization Token Using UUIDv1 | LOW | 0.25% | Nov 22, 2024 |
| CVE-2024-40761 | Apache Answer: Avatar URL leaked user email addresses | MEDIUM | 0.75% | Sep 25, 2024 |
| CVE-2024-41888 | Apache Answer: The link for resetting user password is not Single-Use | MEDIUM | 1.22% | Aug 9, 2024 |
| CVE-2024-41890 | Apache Answer: The link to reset the user's password will remain valid after sending a new link | MEDIUM | 1.15% | Aug 9, 2024 |
| CVE-2024-29217 | Apache Answer: XSS vulnerability when changing personal website | MEDIUM | 0.97% | Apr 21, 2024 |
| CVE-2024-22393 | Apache Answer: Pixel Flood Attack by uploading the large pixel file | HIGH | 2.46% | Feb 22, 2024 |
| CVE-2024-23349 | Apache Answer: XSS vulnerability when submitting summary | MEDIUM | 1.07% | Feb 22, 2024 |
| CVE-2024-26578 | Apache Answer: Repeated submission at registration created duplicate users with the same name | MEDIUM | 0.90% | Feb 22, 2024 |
| CVE-2023-49619 | Apache Answer: Repeated submissions using scripts resulted in an abnormal number of collections for questions. | LOW | 0.89% | Jan 10, 2024 |
Showing 1 to 24 of 24 CVEs