Skip to main content

Vendor/product archive

apache / jackrabbit CVEs

Beta · best-effort

6 CVEs tagged to apache / jackrabbit1 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-58782

Published Sep 8, 2025

Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1;…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-53689

Published Jul 14, 2025

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are re…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-37895

Published Jul 25, 2023

Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branc…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6801

Published Sep 21, 2016

Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1833

Published May 29, 2015

XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0026

Published Jan 21, 2009

Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) sear…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1