Apache Software Foundation Apache Activemq vulnerabilities
28 known vulnerabilities affecting apache_software_foundation/apache_activemq.
Total CVEs
28
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
4
Severity breakdown
CRITICAL1HIGH18MEDIUM8LOW1
Vulnerabilities
Page 2 of 2
CVE-2026-41043P3MEDIUMCVSS 6.5fixed in 5.19.6≥ 6.0.0, < 6.2.52026-04-24
CVE-2026-41043 [MEDIUM] CWE-79 CVE-2026-41043: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field.
This issue affec
nvd
CVE-2026-49270P3MEDIUMCVSS 5.9≥ 5.19.7, < 5.19.8≥ 6.2.6, < 6.2.72026-06-01
CVE-2026-49270 [MEDIUM] CWE-1230 CVE-2026-49270: Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache A
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including cli
nvd
CVE-2016-6810P4MEDIUMCVSS 6.1v5.0.0 to 5.14.12018-01-10
CVE-2016-6810 [MEDIUM] CWE-79 CVE-2016-6810: In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identi
In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.
nvd
CVE-2026-42253P4MEDIUMCVSS 6.1fixed in 5.19.7≥ 6.0.0, < 6.2.62026-06-01
CVE-2026-42253 [MEDIUM] CWE-79 CVE-2026-42253: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
The MessageServlet in the ActiveMQ web console API copies every JMS message
property into an HTTP response header without any validation. This can allow overwriting and injecting security headers by setting them
nvd
CVE-2026-52760P4MEDIUMCVSS 6.1fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-52760 [MEDIUM] CWE-79 CVE-2026-52760: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console.
The browse page in the web console renders a message Id directly without sanitization. This allows an authenticated producer to send a message with a JMS message ID that has been crafted to contain HTML/
nvd
CVE-2017-15709P4LOWCVSS 3.7vApache ActiveMQ 5.14.0 to 5.15.22018-02-13
CVE-2017-15709 [LOW] CWE-200 CVE-2017-15709: When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain sys
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
nvd
CVE-2026-33227P4MEDIUMCVSS 4.3fixed in 5.19.3≥ 6.0.0, < 6.2.22026-04-07
CVE-2026-33227 [MEDIUM] CWE-22 CVE-2026-33227: Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Cli
Improper validation and restriction of a classpath path name vulnerability in
Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.
In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to trav
nvd
CVE-2026-46605P4MEDIUMCVSS 4.3fixed in 5.19.7≥ 6.0.0, < 6.2.62026-06-01
CVE-2026-46605 [MEDIUM] CWE-285 CVE-2026-46605: Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authent
Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7
nvd
← Previous2 / 2