VendorsApachesling_cmsall versions
Vulnerabilities

Apache Software Foundation Sling CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2020-1949
Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.
Published 2020-04-01 · Modified
6.1EPSS 0.020
CVE-2023-22849
Apache Sling App CMS: XSS in CMS Reference / UI Components
Published 2023-02-04 · Modified
6.1EPSS 0.014
CVE-2022-43670
XSS in Sling CMS Reference App Taxonomy Path
Published 2022-11-02 · Modified
5.4EPSS 0.015
CVE-2022-46769
Apache Sling App CMS: XSS in CMS Site Group Detail
Published 2023-01-09 · Modified
5.4EPSS 0.014