CVE-2026-73192
Apache Sling XSS: XSS possible through XSSAPI.getValidHref()
CVSS Score
6.1
EPSS Score
0.2%
EPSS Percentile
11th
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack in every feature using this method. In order to successfully attack an application, the attacker needs to be able to submit a value which is not correctly sanitized by that library. Upgrade to Apache Sling XSS >= 2.4.12
| CWE | CWE-79 |
| Vendor | apache software foundation |
| Product | apache sling xss |
| Published | Sep 23, 2026 |
| Last Updated | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache sling xss
Be the first to know when new medium vulnerabilities affecting apache software foundation apache sling xss are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache Sling XSS
0 < 2.4.12
Credits
Apache Sling would like to thank github user Vectrain51 and n0mi1k for reporting this issue