Skip to main content

Vendor/product archive

apache / tiles CVEs

Beta · best-effort

2 CVEs tagged to apache / tiles0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2023-49735

Published Nov 30, 2023

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1275

Published Apr 9, 2009

Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote atta…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1