Known Vulnerabilities for Apache Sling XSS by Apache Software Foundation
Listed below are 7 of the newest known vulnerabilities associated with "Apache Sling XSS" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-94251 json | A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource ... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-94243 json | A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-92001 json | Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. Th... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-91999 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. Th... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-91928 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. Th... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-91852 json | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. Th... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-73192 json | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the... | Not Provided | 2026-09-23 | 2026-09-23 |