CVE-2026-25688Medium· 6.1▾ SunlitApache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 30.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
github.com/apache/incubator-answer < 1.7.2-0.20260525024654-2746bf5b455fUpgrade to a patched release:
github.com/apache/incubator-answer 1.7.2-0.20260525024654-2746bf5b455fConnected by shared product, vendor, weakness, or advisory.
CVE-2026-25700High· 7.2Apache Answer: AdminToken not invalidated after admin deactivation
CVE-2026-34031Medium· 6.5Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-33582Medium· 6.5Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-34905Medium· 6.5Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2026-34033Medium· 5.4Apache Answer vulnerable to Cross-site Scripting
CVE-2026-25699Medium· 6.1Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability