All 5 CVE vulnerabilities found in Apache Sling XSS, with AI-generated Chinese analysis, references, and POCs.
Vendor: Apache Software Foundation
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-91928 | Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf protection mechanisms CWE-79 | - | - | 2026-09-23 |
| CVE-2026-91852 | Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl CWE-79 | - | - | 2026-09-23 |
| CVE-2026-91999 | Apache Sling XSS: Improper escaping in the XSS Webconsole plugin CWE-79 | - | - | 2026-09-23 |
| CVE-2026-92001 | Apache Sling XSS: Missing parser resource limits CWE-776 | - | - | 2026-09-23 |
| CVE-2026-73192 | Apache Sling XSS: XSS possible through XSSAPI.getValidHref() CWE-79 | - | - | 2026-09-23 |
All 5 known CVE vulnerabilities affecting Apache Sling XSS with full Chinese analysis, references, and POCs where available.