Known Vulnerabilities for Velocity by HCLSoftware
Listed below are 9 of the newest known vulnerabilities associated with "Velocity" by "HCLSoftware".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-94216 json | A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This vuln... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-94214 json | A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects a... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-73649 json | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-20... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-53966 json | XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data ed... | Not Provided | 2026-09-15 | 2026-09-15 |
| CVE-2026-49833 json | DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-49832 json | DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-38165 json | A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-33453 json | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap compo... | Not Provided | 2026-04-27 | 2026-07-15 |
| CVE-2025-12107 json | The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sani... | Not Provided | 2026-02-19 | 2026-09-03 |