📦 Cocoon

by Apache

🔍 What is Cocoon?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-49733

CRITICAL CVSS 9.8 Nov 30, 2023

This CVE describes an XXE (XML External Entity) vulnerability in Apache Cocoon that allows attackers to read arbitrary files from the server or perform server-side request forgery. It affects all Apac...

CVE-2022-45135

CRITICAL CVSS 9.8 Nov 30, 2023

This SQL injection vulnerability in Apache Cocoon allows attackers to execute arbitrary SQL commands on affected systems. It affects Apache Cocoon versions 2.2.0 through 2.3.0 (excluding 2.3.0). Organ...

CVE-2025-24783

HIGH CVSS 7.5 Jan 27, 2025

This vulnerability allows attackers to guess continuation identifiers in Apache Cocoon due to insufficiently random seed values, potentially accessing unauthorized continuations. All versions of Apach...