Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 21 results / 2345 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-76986 Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue — Apache Wicket CWE-79 - - 2026-08-31
CVE-2026-76985 Apache Wicket: XSS in Palette via getAdditionalAttributes — Apache Wicket CWE-79 5.1 Medium 2026-08-31
CVE-2026-76983 Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel — Apache Wicket CWE-79 5.1 Medium 2026-08-31
CVE-2026-76984 Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute — Apache Wicket CWE-79 5.1 Medium 2026-08-31
CVE-2026-76982 Apache Wicket: XSS in Button via its model object — Apache Wicket CWE-79 5.1 Medium 2026-08-31
CVE-2026-75802 Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel — Apache Wicket CWE-79 5.1 Medium 2026-08-31
CVE-2026-71378 Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener — Apache Wicket CWE-352 - - 2026-08-31
CVE-2026-71257 Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed — Apache Wicket CWE-770 - - 2026-08-31
CVE-2026-70449 Apache Wicket: Path traversal in resource style/variation/locale — Apache Wicket CWE-22 - - 2026-08-31
CVE-2026-66391 Apache Wicket: leaked and missing CSP headers — Apache Wicket CWE-330 - - 2026-07-27
CVE-2026-66390 Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence — Apache Wicket CWE-79 - - 2026-07-27
CVE-2026-40010 Apache Wicket: possible session fixation using AuthenticatedWebSession — Apache Wicket 9.8AI Critical AI 2026-05-06
CVE-2026-42509 Apache Wicket: crafted strings can break out of the JavaScript sequence — Apache Wicket CWE-79 6.1AI Medium AI 2026-05-06
CVE-2026-43646 Apache Wicket: crafted URLs can bypass PackageResourceGuard — Apache Wicket CWE-200 7.5AI High AI 2026-05-06
CVE-2026-43975 Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager — Apache Wicket CWE-22 9.1AI Critical AI 2026-05-06
CVE-2024-53299 Apache Wicket: An attacker can intentionally trigger a memory leak — Apache Wicket CWE-400 7.5 - 2025-01-23
CVE-2024-36522 Apache Wicket: Remote code execution via XSLT injection — Apache Wicket CWE-74 9.8AI Critical AI 2024-07-12
CVE-2024-27439 Apache Wicket: Possible bypass of CSRF protection — Apache Wicket CWE-352 8.8 - 2024-03-19
CVE-2021-23937 DNS proxy and possible amplification attack — Apache Wicket 7.5 - 2021-05-25
CVE-2014-0043 Apache Wicket 信息泄露漏洞 — Apache Wicket 5.3 - 2017-10-02
CVE-2016-6806 Apache Wicket 跨站请求伪造漏洞 — Apache Wicket 8.8 - 2017-10-02

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.