Skip to main content

Vendor/product archive

apache / vcl CVEs

Beta · best-effort

3 CVEs tagged to apache / vcl0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-53679

Published Mar 25, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with sufficient rights to be able…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53678

Published Mar 25, 2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitted when requesting a new Block…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0267

Published Feb 21, 2018

The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin, manageGroup,…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1