VendorsApachejackrabbitall versions
Vulnerabilities

Apache Jackrabbit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-37895
Apache Jackrabbit RMI access can lead to RCE
Published 2023-07-25 · Modified
9.8EPSS 0.032
CVE-2016-6801
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.
Published 2016-09-21 · Modified
8.8EPSS 0.023
CVE-2025-53689
Apache Jackrabbit: XXE vulnerability in jackrabbit-spi-commons
Published 2025-07-14 · Modified
8.8EPSS 0.005
CVE-2025-58782
Apache Jackrabbit Core, Apache Jackrabbit JCR Commons: JNDI injection risk with JndiRepositoryFactory
Published 2025-09-08 · Analyzed
6.5EPSS 0.013
CVE-2015-1833
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary files and send requests to intranet servers via a crafted WebDAV request.
Published 2015-05-29 · Modified
6.41 PoCEPSS 0.550
CVE-2009-0026
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
Published 2009-01-21 · Modified
4.32 PoCEPSS 0.268