📦 Syncope

by Apache

🔍 What is Syncope?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-65998

HIGH CVSS 7.5 Nov 24, 2025

Apache Syncope versions before 3.0.15 and 4.0.3 use a hard-coded AES encryption key for password storage when configured to encrypt passwords in the database. This allows attackers who gain database a...

CVE-2026-23794

MEDIUM CVSS 6.8 Feb 3, 2026

This reflected XSS vulnerability in Apache Syncope's Enduser Login page allows attackers to steal user credentials by tricking legitimate users into clicking malicious links. It affects Apache Syncope...

CVE-2026-23795

MEDIUM CVSS 4.9 Feb 3, 2026

This CVE describes an XXE vulnerability in Apache Syncope Console that allows administrators with Keymaster parameter privileges to inject malicious XML. Successful exploitation could lead to sensitiv...

CVE-2024-45031

MEDIUM CVSS 6.1 Oct 24, 2024

This stored cross-site scripting (XSS) vulnerability in Apache Syncope allows attackers to inject malicious scripts through incomplete HTML tags that bypass sanitization. Both Syncope Console administ...

CVE-2024-38503

MEDIUM CVSS 5.4 Jul 22, 2024

This vulnerability allows attackers to inject HTML tags into text fields in Apache Syncope's Console and Enduser interfaces. When exploited, it enables cross-site scripting (XSS) attacks that could co...