Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 1840

Browse all 1840 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 18 results / 1840Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-25700 Apache Answer: AdminToken not invalidated after admin deactivation — Apache AnswerCWE-1259--2026-06-10
CVE-2026-34905 Apache Answer: Unlisted Questions Accessible via Direct API Access — Apache AnswerCWE-200--2026-06-09
CVE-2026-34033 Apache Answer: HTML Content Injection in Email — Apache AnswerCWE-80--2026-06-09
CVE-2026-34031 Apache Answer: The custom avatar was not properly validated — Apache AnswerCWE-434--2026-06-09
CVE-2026-33582 Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error — Apache AnswerCWE-434--2026-06-09
CVE-2026-25699 Apache Answer: Authorization Bypass in Timeline API — Apache AnswerCWE-359--2026-06-09
CVE-2026-25688 Apache Answer: XSS in AI Answer Rendering — Apache AnswerCWE-87--2026-06-09
CVE-2026-24735 Apache Answer: Revision API Improper Access Control leads to Information Disclosure — Apache AnswerCWE-359 5.3AIMediumAI2026-02-04
CVE-2025-29868 Apache Answer: Using externally referenced images can leak user privacy. — Apache AnswerCWE-495 6.5 -2025-04-01
CVE-2024-45719 Apache Answer: Predictable Authorization Token Using UUIDv1 — Apache AnswerCWE-326 7.5 -2024-11-22
CVE-2024-40761 Apache Answer: Avatar URL leaked user email addresses — Apache AnswerCWE-326 7.5AIHighAI2024-09-25
CVE-2024-41888 Apache Answer: The link for resetting user password is not Single-Use — Apache AnswerCWE-772 7.5AIHighAI2024-08-09
CVE-2024-41890 Apache Answer: The link to reset the user's password will remain valid after sending a new link — Apache AnswerCWE-772 7.5AIHighAI2024-08-09
CVE-2024-29217 Apache Answer: XSS vulnerability when changing personal website — Apache AnswerCWE-79 5.4 -2024-04-21
CVE-2024-22393 Apache Answer: Pixel Flood Attack by uploading the large pixel file — Apache AnswerCWE-434 6.5 -2024-02-22
CVE-2024-23349 Apache Answer: XSS vulnerability when submitting summary — Apache AnswerCWE-79 5.4 -2024-02-22
CVE-2024-26578 Apache Answer: Repeated submission at registration created duplicate users with the same name — Apache AnswerCWE-362 7.4 -2024-02-22
CVE-2023-49619 Apache Answer: Repeated submissions using scripts resulted in an abnormal number of collections for questions. — Apache AnswerCWE-362--AI2024-01-10

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.