Skip to main content

Vendor/product archive

apache / cocoon CVEs

Beta · best-effort

5 CVEs tagged to apache / cocoon2 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2025-24783

Published Jan 27, 2025

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects Apache Cocoon: all versions.…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-49733

Published Nov 30, 2023

Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-45135

Published Nov 30, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Use…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-11991

Published Sep 11, 2020

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server sys…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1172

Published Dec 31, 2003

Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot d…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1