VendorsApachesling_apiall versions
Vulnerabilities

Apache Sling API

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2022-32549
log injection in Sling logging
Published 2022-06-22 · Modified
5.3EPSS 0.024
CVE-2015-2944
Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.
Published 2015-06-02 · Modified
4.3EPSS 0.063