Apache / Myfaces
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-26296 | Cross-Site Request Forgery (CSRF) vulnerability in Apache MyFaces | HIGH | 7.5 | Feb 19, 2021 |
| CVE-2011-4343 | 2: EL injection, includeViewParameters re-evaluates param/model values as EL expressions | HIGH | 7.5 | Aug 8, 2017 |
| CVE-2011-4367 | MyFaces: multiple directory traversal vulnerabilities allow remote attackers to read arbitrary files | HIGH | 7.5 | Jun 19, 2014 |
| CVE-2010-2057 | shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Aut… | MEDIUM | 5.0 | Oct 20, 2010 |
| CVE-2010-2086 | MyFaces: XSS via state view | MEDIUM | 4.0 | May 27, 2010 |
Showing 1 to 5 of 5 CVEs