Apache / Syncope
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-62418 | Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check | HIGH | 8.1 | Jul 20, 2026 |
| CVE-2026-62183 | Apache Syncope: User self-service privilege escalation | CRITICAL | 9.8 | Jul 20, 2026 |
| CVE-2026-57308 | Apache Syncope: SQL injection vulnerability in Audit Events search | CRITICAL | 9.8 | Jul 20, 2026 |
| CVE-2026-53421 | Apache Syncope: Remote Code Execution via Scripted Connector | CRITICAL | 9.8 | Jul 20, 2026 |
| CVE-2026-53405 | Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask | CRITICAL | 9.8 | Jul 20, 2026 |
| CVE-2026-63071 | Apache Syncope: RCE via Groovy Sandbox bypass | CRITICAL | 9.8 | Jul 20, 2026 |
| CVE-2026-42797 | Apache Syncope: JexlContextBuilder Information Disclosure | MEDIUM | 4.9 | May 25, 2026 |
| CVE-2026-42782 | Apache Syncope: Post-auth RCE via Groovy static | HIGH | 7.2 | May 25, 2026 |
| CVE-2026-23794 | Apache Syncope: Reflected XSS on Enduser Login | MEDIUM | 6.8 | Feb 3, 2026 |
| CVE-2026-23795 | Apache Syncope: Console XXE on Keymaster parameters | MEDIUM | 4.9 | Feb 3, 2026 |
| CVE-2025-65998 | Apache Syncope: Default AES key used for internal password encryption | HIGH | 7.5 | Nov 24, 2025 |
| CVE-2025-57738 | Apache Syncope: Remote Code Execution by delegated administrators | HIGH | 7.2 | Oct 20, 2025 |
| CVE-2024-45031 | Apache Syncope: Stored XSS in Console and Enduser | MEDIUM | 5.1 | Oct 24, 2024 |
| CVE-2024-38503 | Apache Syncope: HTML tags can be injected into Console or Enduser text fields | HIGH | 7.1 | Jul 22, 2024 |
| CVE-2020-11977 | In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Task… | HIGH | 7.2 | Sep 15, 2020 |
| CVE-2020-1961 | Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling at… | HIGH | 9.8 | May 4, 2020 |
| CVE-2019-17557 | It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the… | LOW | 5.4 | May 4, 2020 |
| CVE-2020-1959 | A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unau… | CRITICAL | 9.8 | May 4, 2020 |
| CVE-2018-17186 | An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and cod… | HIGH | 7.2 | Nov 6, 2018 |
| CVE-2018-17184 | A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, Any… | MEDIUM | 5.4 | Nov 6, 2018 |
| CVE-2018-1322 | An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be… | MEDIUM | 4.9 | Mar 20, 2018 |
| CVE-2018-1321 | An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x whic… | HIGH | 7.2 | Mar 20, 2018 |
| CVE-2014-3503 | Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute f… | MEDIUM | 5.0 | Jul 11, 2014 |
| CVE-2014-0111 | Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL… | MEDIUM | 6.5 | Apr 17, 2014 |
Showing 1 to 24 of 24 CVEs