Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/org.apache.answer/apache-answer

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-60023 is a high-severity vulnerability in Apache Answer versions prior to 2.0.2. It allows unauthorized users to retrieve deleted or pending answers through the single-answer read path if the parent question remains visible, exposing sensitive information that should not be accessible. The issue is fixed in version 2.0.2.

Join the discussion

An improper input validation vulnerability exists in Apache Answer through version 2.0.1. The issue arises from a missing ownership check in the avatar-cleanup logic, allowing any authenticated user to delete files uploaded by other users by supplying their file URLs. The vulnerability is fixed in version 2.0.2.

Join the discussion

Apache Answer versions through 2.0.1 contain an insufficient verification of data authenticity vulnerability. This flaw is due to a missing authorization check in the external-login email binding flow, which allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link. The issue is fixed in version 2.0.2.

Join the discussion

CVE-2026-48834 is a high-severity vulnerability in Apache Answer up to version 2.0.1. It involves improper handling of length parameter inconsistencies in the Accept-Language header, allowing unauthenticated attackers to cause denial of service by triggering excessive CPU consumption during parsing. The issue is fixed in version 2.0.2.

Join the discussion

CVE-2026-34033 is a medium severity vulnerability in Apache Answer affecting versions before 2.0.1. It involves improper neutralization of script-related HTML tags (basic XSS) where user-supplied content is included in notification emails without proper escaping. This allows authenticated users to inject arbitrary HTML into emails sent to other users. The issue is fixed in Apache Answer version 2.0.1.

Join the discussion

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Join the discussion

CVE-2026-25688 is a medium severity vulnerability in Apache Answer up to version 2.0.0. It involves improper neutralization of alternate cross-site scripting (XSS) syntax in AI-generated response content, which is rendered in the browser without proper sanitization. This flaw allows malicious scripts to execute when the content is viewed. The issue is fixed in version 2.0.1.

Join the discussion

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unauthorized user to retrieve restricted or sensitive information. Users are recommended to upgrade to version 2.0.0, which fixes the issue.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:maven/org.apache.answer/apache-answer
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses