Apache / Cocoon
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-24783 | Apache Cocoon: continuations may not be private | LOW | 2.7 | Jan 27, 2025 |
| CVE-2023-49733 | Apache Cocoon's StreamGenerator is vulnerable to XXE injection | CRITICAL | 9.8 | Nov 30, 2023 |
| CVE-2022-45135 | Apache Cocoon: SQL injection in DatabaseCookieAuthenticatorAction | CRITICAL | 9.8 | Nov 30, 2023 |
| CVE-2020-11991 | When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any fi… | HIGH | 7.5 | Sep 11, 2020 |
| CVE-2003-1172 | Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary f… | MEDIUM | 5.0 | May 10, 2005 |
Showing 1 to 5 of 5 CVEs