Skip to content

Known CVE

Apache Cocoon 2.1.12 - XML Injection

Apache Cocoon 2.1.12 is susceptible to XML injection. When using the StreamGenerator, the code parses a user-provided XML. A specially crafted XML, including external system entities, can be used to access any file on the server system.

CVE-2020-11991

High2020CVSS 7.5CWE-611

cve2020 · apache · xml · cocoon · xxe · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website