📦 Answer

by Apache

🔍 What is Answer?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-22393

CRITICAL CVSS 9.1 Feb 22, 2024

This vulnerability allows authenticated users to upload large image files that consume excessive server memory, potentially causing denial of service. It affects Apache Answer installations up to vers...

CVE-2026-24735

HIGH CVSS 7.5 Feb 4, 2026

An unauthenticated API endpoint in Apache Answer exposes full revision history for deleted content, allowing unauthorized users to retrieve sensitive information. This affects all Apache Answer instal...

CVE-2025-29868

MEDIUM CVSS 6.5 Apr 1, 2025

This vulnerability in Apache Answer allows external image providers to obtain the IP addresses of users who view their images. It affects all Apache Answer installations through version 1.4.2. The iss...

CVE-2024-40761

MEDIUM CVSS 5.3 Sep 25, 2024

This vulnerability in Apache Answer uses weak MD5 hashing of user email addresses for Gravatar integration, potentially exposing email addresses through hash reversal attacks. It affects all Apache An...

CVE-2024-41888

MEDIUM CVSS 5.3 Aug 12, 2024

Apache Answer versions through 1.3.5 have a vulnerability where password reset links remain valid after being used, allowing potential account takeover. This affects all users of affected Apache Answe...