VendorsApachevclall versions
Vulnerabilities

Apache Software Foundation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2013-0267
The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin, manageGroup, resourceGrant, or userGrant permissions to gain privileges, cause a denial of service, or conduct cross-site scripting (XSS) attacks by leveraging improper data validation.
Published 2018-02-21 · Modified
8.8EPSS 0.037
CVE-2024-53678
Apache VCL: SQL injection vulnerability in New Block Allocation form
Published 2025-03-25 · Analyzed
8.8EPSS 0.006
CVE-2024-53679
Apache VCL: XSS vulnerability in User Lookup impacting user privileges
Published 2025-03-25 · Analyzed
8.4EPSS 0.005