CVE-2026-34033Medium· 5.4▾ SunlitApache Answer vulnerable to Cross-site Scripting
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 31.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
User-supplied content was included in notification emails without proper escaping, allowing authenticated users to inject arbitrary HTML into emails sent to other users. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
github.com/apache/incubator-answer < 1.7.2-0.20260509080709-d1a4092c61ccUpgrade to a patched release:
github.com/apache/incubator-answer 1.7.2-0.20260509080709-d1a4092c61ccConnected by shared product, vendor, weakness, or advisory.
CVE-2026-25700High· 7.2Apache Answer: AdminToken not invalidated after admin deactivation
CVE-2026-34031Medium· 6.5Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-33582Medium· 6.5Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-34905Medium· 6.5Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2026-25699Medium· 6.1Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
CVE-2026-25688Medium· 6.1Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability