VendorsApachelog4cxxall versions
Vulnerabilities

Apache Software Foundation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-31038
Apache Log4cxx: SQL injection when using ODBC appender
Published 2023-05-08 · Modified
8.8EPSS 0.016
CVE-2025-54813
Apache Log4cxx: Improper escaping with JSONLayout
Published 2025-08-22 · Modified
7.5EPSS 0.013
CVE-2026-40023
Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters
Published 2026-04-10 · Analyzed
6.3EPSS 0.010
CVE-2025-54812
Apache Log4cxx: Improper HTML escaping in HTMLLayout
Published 2025-08-22 · Modified
5.4EPSS 0.012