Apache / Sling
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-45064 | Apache Sling Engine: Include-based XSS | CRITICAL | 9.0 | Apr 13, 2023 |
| CVE-2016-6798 | In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which al… | CRITICAL | 9.8 | Jul 19, 2017 |
| CVE-2016-5394 | In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough and for so… | MEDIUM | 6.1 | Jul 19, 2017 |
| CVE-2016-0956 | The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive inf… | HIGH | 7.5 | Feb 10, 2016 |
| CVE-2013-4390 | Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Sling allows r… | MEDIUM | 4.7 | Oct 24, 2013 |
Showing 1 to 5 of 5 CVEs