Skip to main content

Vendor/product archive

apache / answer CVEs

Beta · best-effort

18 CVEs tagged to apache / answer1 Critical, 2 High, 13 Medium, 2 Low, 0 Unrated.

CVE-2026-25700

Published Jun 10, 2026

Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were n…

CVSS 7.2 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-34905

Published Jun 9, 2026

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-34033

Published Jun 9, 2026

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. User-supplied cont…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-34031

Published Jun 9, 2026

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-su…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-33582

Published Jun 9, 2026

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive mem…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-25699

Published Jun 9, 2026

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked p…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-25688

Published Jun 9, 2026

Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in th…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24735

Published Feb 4, 2026

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticated API endpoin…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-29868

Published Apr 1, 2025

Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced ima…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45719

Published Nov 22, 2024

Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent no…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-40761

Published Sep 25, 2024

Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's email to access Gravatar is insec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41890

Published Aug 12, 2024

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails,…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41888

Published Aug 12, 2024

Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. The password reset link remains valid withi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29217

Published Apr 21, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack whe…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26578

Published Feb 22, 2024

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Repeat…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23349

Published Feb 22, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. XSS attack wh…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22393

Published Feb 22, 2024

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-49619

Published Jan 10, 2024

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Unde…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1