Upgrade to Apache Sling XSS >= 2.4.12
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 23 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack in every feature using this method. In order to successfully attack an application, the attacker needs to be able to submit a value which is not correctly sanitized by that library. Upgrade to Apache Sling XSS >= 2.4.12 | |
| Title | Apache Sling XSS: XSS possible through XSSAPI.getValidHref() | |
| Weaknesses | CWE-79 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-09-23T17:08:11.709Z
Reserved: 2026-08-11T11:21:29.423Z
Link: CVE-2026-73192
Updated: 2026-09-23T14:06:11.671Z
Status : Received
Published: 2026-09-23T10:17:07.660
Modified: 2026-09-23T17:17:16.373
Link: CVE-2026-73192
No data.
OpenCVE Enrichment
Updated: 2026-09-23T17:30:06Z