Apache Activemq Web vulnerabilities
4 known vulnerabilities affecting apache/activemq_web.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2026-41043P3MEDIUMCVSS 6.5fixed in 5.19.6≥ 6.0.0, < 6.2.52026-04-24
CVE-2026-41043 [MEDIUM] CWE-79 CVE-2026-41043: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field.
This issue affec
nvd
CVE-2026-42253P4MEDIUMCVSS 6.1fixed in 5.19.7≥ 6.0.0, < 6.2.62026-06-01
CVE-2026-42253 [MEDIUM] CWE-79 CVE-2026-42253: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
The MessageServlet in the ActiveMQ web console API copies every JMS message
property into an HTTP response header without any validation. This can allow overwriting and injecting security headers by setting them
nvd
CVE-2026-52760P4MEDIUMCVSS 6.1fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-52760 [MEDIUM] CWE-79 CVE-2026-52760: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console.
The browse page in the web console renders a message Id directly without sanitization. This allows an authenticated producer to send a message with a JMS message ID that has been crafted to contain HTML/
nvd
CVE-2026-33227P4MEDIUMCVSS 4.3fixed in 5.19.3≥ 6.0.0, < 6.2.22026-04-07
CVE-2026-33227 [MEDIUM] CWE-22 CVE-2026-33227: Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Cli
Improper validation and restriction of a classpath path name vulnerability in
Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.
In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to trav
nvd