| CVE-2026-80190 | medium | — | Apache Allura: stored XSS via SVN code repositories. Git repositories are not known to be affected.… | Sep 4, 2026 | Sep 4, 2026 |
| CVE-2026-85229 | medium | — | ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-… | Sep 4, 2026 | Sep 4, 2026 |
| CVE-2026-81270 | medium | — | Apache Allura: exposure of non-public information via search.
This issue affects Apache Allura: t… | Sep 4, 2026 | Sep 4, 2026 |
| CVE-2026-71216 | medium | — | PagerDuty alarm hook transmits the integration routing key over cleartext HTTP.
PagerDuty serves … | Sep 4, 2026 | Sep 4, 2026 |
| CVE-2026-80181 | medium | — | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affect… | Sep 4, 2026 | Sep 4, 2026 |
| CVE-2026-80180 | medium | — | Stored XSS via markdown HTML processing in Apache Allura.
This issue affects Apache Allura: from … | Sep 4, 2026 | Sep 4, 2026 |
| CVE-2026-32773 | medium | 6.1 | There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious … | Sep 2, 2026 | Sep 3, 2026 |
| CVE-2026-84218 | high | 8.1 | A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-co… | Sep 1, 2026 | Sep 2, 2026 |
| CVE-2026-17615 | high | 7.5 | A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker… | Aug 31, 2026 | Sep 4, 2026 |
| CVE-2026-76986 | medium | 6.1 | Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.mar… | Aug 31, 2026 | Sep 1, 2026 |
| CVE-2026-76985 | medium | 5.4 | Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.ext… | Aug 31, 2026 | Sep 1, 2026 |
| CVE-2026-12894 | high | 8.8 | A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content l… | Aug 31, 2026 | Sep 3, 2026 |
| CVE-2026-76984 | medium | 5.4 | Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.mar… | Aug 31, 2026 | Sep 1, 2026 |
| CVE-2026-76983 | medium | 5.4 | Improper neutralization of input during web page generation in Apache Wicket.
The <wicket:label> ta… | Aug 31, 2026 | Sep 1, 2026 |
| CVE-2026-76982 | medium | 5.4 | Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket.mar… | Aug 31, 2026 | Sep 1, 2026 |
| CVE-2026-75802 | medium | 5.4 | AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writ… | Aug 31, 2026 | Sep 1, 2026 |
| CVE-2026-71378 | medium | 4.6 | ResourceIsolationRequestCycleListener protects a Wicket application against cross-site request forge… | Aug 31, 2026 | Sep 1, 2026 |
| CVE-2026-71257 | high | 7.5 | Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multip… | Aug 31, 2026 | Sep 1, 2026 |
| CVE-2026-70449 | medium | 5.3 | Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote att… | Aug 31, 2026 | Sep 1, 2026 |
| CVE-2026-58301 | medium | 6.5 | When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an… | Aug 31, 2026 | Sep 1, 2026 |
| CVE-2026-5680 | high | 7.5 | A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending speciall… | Aug 27, 2026 | Sep 4, 2026 |
| CVE-2026-75020 | high | 8.1 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability i… | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-75005 | high | 7.5 | Inefficient Algorithmic Complexity vulnerability in Apache APISIX.
A single small request can pin … | Aug 27, 2026 | Aug 28, 2026 |
| CVE-2026-74848 | high | 7.5 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap… | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-63041 | high | 8.8 | Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX.
This vulnerabil… | Aug 26, 2026 | Aug 27, 2026 |