VendorsApacheanswerany version
Vulnerabilities

Apache Answer any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2024-22393
Apache Answer: Pixel Flood Attack by uploading the large pixel file
Published 2024-02-22 · Analyzed
9.1EPSS 0.025
CVE-2026-60053
Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
Published 2026-08-05 · Analyzed
9.1EPSS 0.003
CVE-2026-24735
Apache Answer: Revision API Improper Access Control leads to Information Disclosure
Published 2026-02-04 · Analyzed
7.5EPSS 0.006
CVE-2026-48834
Apache Answer: Denial of service via crafted Accept-Language header parsing
Published 2026-08-05 · Analyzed
7.5EPSS 0.005
CVE-2026-60023
Apache Answer: Unauthorized disclosure of deleted or pending answer content
Published 2026-08-05 · Analyzed
7.5EPSS 0.004
CVE-2026-48911
Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
Published 2026-08-05 · Analyzed
7.5EPSS 0.004
CVE-2026-25700
Apache Answer: AdminToken not invalidated after admin deactivation
Published 2026-06-10 · Modified
7.2EPSS 0.004
CVE-2025-29868
Apache Answer: Using externally referenced images can leak user privacy.
Published 2025-04-01 · Analyzed
6.5EPSS 0.009
CVE-2026-33582
Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error
Published 2026-06-09 · Analyzed
6.5EPSS 0.005
CVE-2026-34031
Apache Answer: The custom avatar was not properly validated
Published 2026-06-09 · Analyzed
6.5EPSS 0.004
CVE-2026-34905
Apache Answer: Unlisted Questions Accessible via Direct API Access
Published 2026-06-09 · Analyzed
6.5EPSS 0.003
CVE-2026-50749
Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
Published 2026-08-05 · Analyzed
6.5EPSS 0.003
CVE-2026-48912
Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL
Published 2026-08-05 · Analyzed
6.5EPSS 0.003
CVE-2026-25688
Apache Answer: XSS in AI Answer Rendering
Published 2026-06-09 · Analyzed
6.1EPSS 0.004
CVE-2026-25699
Apache Answer: Authorization Bypass in Timeline API
Published 2026-06-09 · Analyzed
6.1EPSS 0.004
CVE-2024-26578
Apache Answer: Repeated submission at registration created duplicate users with the same name
Published 2024-02-22 · Modified
5.9EPSS 0.009
CVE-2024-23349
Apache Answer: XSS vulnerability when submitting summary
Published 2024-02-22 · Modified
5.4EPSS 0.011
CVE-2026-34033
Apache Answer: HTML Content Injection in Email
Published 2026-06-09 · Analyzed
5.4EPSS 0.003
CVE-2024-41888
Apache Answer: The link for resetting user password is not Single-Use
Published 2024-08-09 · Modified
5.3EPSS 0.012
CVE-2024-41890
Apache Answer: The link to reset the user's password will remain valid after sending a new link
Published 2024-08-09 · Modified
5.3EPSS 0.011
CVE-2024-40761
Apache Answer: Avatar URL leaked user email addresses
Published 2024-09-25 · Analyzed
5.3EPSS 0.007
CVE-2024-29217
Apache Answer: XSS vulnerability when changing personal website
Published 2024-04-21 · Analyzed
4.6EPSS 0.010
CVE-2023-49619
Apache Answer: Repeated submissions using scripts resulted in an abnormal number of collections for questions.
Published 2024-01-10 · Modified
3.1EPSS 0.009
CVE-2024-45719
Apache Answer: Predictable Authorization Token Using UUIDv1
Published 2024-11-22 · Analyzed
2.6EPSS 0.002