Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Cocoon
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49733 1 Apache 1 Cocoon 2023-12-05 N/A 9.8 CRITICAL
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
CVE-2022-45135 1 Apache 1 Cocoon 2023-12-05 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.