Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache Answer — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in Apache Answer, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Apache Answer product, classified under the "product" entity. The page collects known security flaws affecting Answer, covering a specific historical time range to provide a consolidated view of its security posture. Readers can use this resource to track vendor advisories, understand recurring weakness classes within the product's ecosystem, and review the complete vulnerability history for Apache Answer.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-60053 Apache Answer: Residual Administrative API Key Access After Role or Account Revocation CWE-613 - - 2026-08-05
CVE-2026-60023 Apache Answer: Unauthorized disclosure of deleted or pending answer content CWE-200 - - 2026-08-05
CVE-2026-50749 Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions CWE-863 - - 2026-08-05
CVE-2026-48912 Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL CWE-639 - - 2026-08-05
CVE-2026-48911 Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow CWE-306 - - 2026-08-05
CVE-2026-48834 Apache Answer: Denial of service via crafted Accept-Language header parsing CWE-400 - - 2026-08-05
CVE-2026-25700 Apache Answer: AdminToken not invalidated after admin deactivation CWE-1259 - - 2026-06-10
CVE-2026-34905 Apache Answer: Unlisted Questions Accessible via Direct API Access CWE-200 - - 2026-06-09
CVE-2026-34033 Apache Answer: HTML Content Injection in Email CWE-80 - - 2026-06-09
CVE-2026-34031 Apache Answer: The custom avatar was not properly validated CWE-434 - - 2026-06-09
CVE-2026-33582 Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error CWE-434 - - 2026-06-09
CVE-2026-25699 Apache Answer: Authorization Bypass in Timeline API CWE-359 - - 2026-06-09
CVE-2026-25688 Apache Answer: XSS in AI Answer Rendering CWE-87 - - 2026-06-09
CVE-2026-24735 Apache Answer: Revision API Improper Access Control leads to Information Disclosure CWE-359 5.3AI Medium AI 2026-02-04
CVE-2025-29868 Apache Answer: Using externally referenced images can leak user privacy. CWE-495 6.5 - 2025-04-01
CVE-2024-45719 Apache Answer: Predictable Authorization Token Using UUIDv1 CWE-326 7.5 - 2024-11-22
CVE-2024-40761 Apache Answer: Avatar URL leaked user email addresses CWE-326 7.5AI High AI 2024-09-25
CVE-2024-41888 Apache Answer: The link for resetting user password is not Single-Use CWE-772 7.5AI High AI 2024-08-09
CVE-2024-41890 Apache Answer: The link to reset the user's password will remain valid after sending a new link CWE-772 7.5AI High AI 2024-08-09
CVE-2024-29217 Apache Answer: XSS vulnerability when changing personal website CWE-79 5.4 - 2024-04-21
CVE-2024-22393 Apache Answer: Pixel Flood Attack by uploading the large pixel file CWE-434 6.5 - 2024-02-22
CVE-2024-23349 Apache Answer: XSS vulnerability when submitting summary CWE-79 5.4 - 2024-02-22
CVE-2024-26578 Apache Answer: Repeated submission at registration created duplicate users with the same name CWE-362 7.4 - 2024-02-22
CVE-2023-49619 Apache Answer: Repeated submissions using scripts resulted in an abnormal number of collections for questions. CWE-362 - - AI 2024-01-10

All 24 known CVE vulnerabilities affecting Apache Answer with full Chinese analysis, references, and POCs where available.