Vulnerabilities > Apache > Cocoon > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-11-30 CVE-2023-49733 Unspecified vulnerability in Apache Cocoon 2.2.0
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
network
low complexity
apache
critical
9.8
2023-11-30 CVE-2022-45135 Unspecified vulnerability in Apache Cocoon 2.2.0
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
network
low complexity
apache
critical
9.8