Known Vulnerabilities for Solr by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Solr" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56096 json | The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax s... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-56094 json | The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's o... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-56093 json | The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user acces... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-48203 json | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-44825 json | Not Provided | 2026-06-01 | 2026-07-22 | |
| CVE-2021-44548 json | An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC pa... | 9.8 - CRITICAL | 2021-12-23 | 2022-08-09 |
| CVE-2021-33813 json | An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. | 7.5 - HIGH | 2021-06-16 | 2023-11-07 |
| CVE-2021-29943 json | When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy ... | 9.1 - CRITICAL | 2021-04-13 | 2021-06-08 |
| CVE-2021-29262 json | When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACL... | 7.5 - HIGH | 2021-04-13 | 2023-11-07 |
| CVE-2021-28164 json | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e... | 5.3 - MEDIUM | 2021-04-01 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Solr | 8.6.3 | |||
| Application | Apache | Solr | 8.6.2 | |||
| Application | Apache | Solr | 8.6.1 | |||
| Application | Apache | Solr | 8.6.0 | |||
| Application | Apache | Solr | 8.5.2 | |||
| Application | Apache | Solr | 8.5.1 | |||
| Application | Apache | Solr | 8.5.0 | |||
| Application | Apache | Solr | 8.4.1 | |||
| Application | Apache | Solr | 8.4.0 | |||
| Application | Apache | Solr | 8.3.1 | |||
| Application | Apache | Solr | 8.3.0 | |||
| Application | Apache | Solr | 8.2.0 | |||
| Application | Apache | Solr | 8.1.1 | |||
| Application | Apache | Solr | 8.1.0 | |||
| Application | Apache | Solr | 8.0.0 | |||
| Application | Apache | Solr | 7.7.3 | |||
| Application | Apache | Solr | 7.7.2 | |||
| Application | Apache | Solr | 7.7.1 | |||
| Application | Apache | Solr | 7.7.0 | |||
| Application | Apache | Solr | 7.6.0 |