Oracle Application Express vulnerabilities

47 known vulnerabilities affecting oracle/application_express.

Total CVEs
47
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL4HIGH2MEDIUM41

Vulnerabilities

Page 1 of 3
CVE-2025-50067CRITICALCVSS 9.0v24.2.4v24.2.52025-07-15
CVE-2025-50067 [CRITICAL] CWE-601 CVE-2025-50067: Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported v Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other t
nvd
CVE-2025-21557MEDIUMCVSS 5.4v23.2v24.12025-01-21
CVE-2025-21557 [MEDIUM] CWE-863 CVE-2025-21557: Vulnerability in Oracle Application Express (component: General). Supported versions that are affec Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while t
nvd
CVE-2024-21261MEDIUMCVSS 4.9v23.2v24.12024-10-15
CVE-2024-21261 [MEDIUM] CVE-2024-21261: Vulnerability in Oracle Application Express (component: General). Supported versions that are affec Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. While the vulnerability is in Oracle Application Express, attacks may significantly impact additiona
nvd
CVE-2023-21974CRITICALCVSS 9.0≥ 18.2, ≤ 22.12023-07-18
CVE-2023-21974 [CRITICAL] CVE-2023-21974: Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Team Calendar Plugin: 18.2-22.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Team Calen
nvd
CVE-2023-21975CRITICALCVSS 9.0≥ 18.2, ≤ 22.22023-07-18
CVE-2023-21975 [CRITICAL] CVE-2023-21975: Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (com Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Customers Plugin: 18.2-22.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Customers Plugin.
nvd
CVE-2023-21983MEDIUMCVSS 5.6≥ 18.2, ≤ 22.22023-07-18
CVE-2023-21983 [MEDIUM] CVE-2023-21983: Vulnerability in the Application Express Administration product of Oracle Application Express (compo Vulnerability in the Application Express Administration product of Oracle Application Express (component: None). Supported versions that are affected are Application Express Administration: 18.2-22.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Express Administration. Successful a
nvd
CVE-2022-24729HIGHCVSS 7.5fixed in 22.1.12022-03-16
CVE-2022-24729 [MEDIUM] CWE-400 CVE-2022-24729: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.1 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.
nvd
CVE-2022-24728MEDIUMCVSS 5.4fixed in 22.1.12022-03-16
CVE-2022-24728 [MEDIUM] CWE-79 CVE-2022-24728: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been disco CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. T
nvd
CVE-2021-41164MEDIUMCVSS 5.4fixed in 22.12021-11-17
CVE-2021-41164 [HIGH] CWE-79 CVE-2021-41164: CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been disco CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users usin
nvd
CVE-2021-41165MEDIUMCVSS 5.4fixed in 22.12021-11-17
CVE-2021-41165 [HIGH] CWE-79 CVE-2021-41165: CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discov CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using
nvd
CVE-2021-41182MEDIUMCVSS 6.1fixed in 22.1.12021-10-26
CVE-2021-41182 [MEDIUM] CWE-79 CVE-2021-41182: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not acc
nvd
CVE-2021-41183MEDIUMCVSS 6.1fixed in 22.1.12021-10-26
CVE-2021-41183 [MEDIUM] CWE-79 CVE-2021-41183: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is
nvd
CVE-2021-41184MEDIUMCVSS 6.1fixed in 22.1.12021-10-26
CVE-2021-41184 [MEDIUM] CWE-79 CVE-2021-41184: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the val
nvd
CVE-2021-37695MEDIUMCVSS 5.4fixed in 21.1.42021-08-13
CVE-2021-37695 [HIGH] CWE-79 CVE-2021-37695: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEdito
nvd
CVE-2021-32808MEDIUMCVSS 5.4fixed in 21.1.42021-08-12
CVE-2021-32808 [HIGH] CWE-79 CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been d ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor
nvd
CVE-2021-32809MEDIUMCVSS 5.4fixed in 21.1.42021-08-12
CVE-2021-32809 [MEDIUM] CWE-94 CVE-2021-32809: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all
nvd
CVE-2021-2460MEDIUMCVSS 5.4fixed in 21.1.0.00.042021-07-21
CVE-2021-2460 [MEDIUM] CVE-2021-2460: Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. T Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 21.1.0.00.04. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Data Reporter. Successful a
nvd
CVE-2021-32723MEDIUMCVSS 6.5fixed in 21.1.42021-06-28
CVE-2021-32723 [HIGH] CWE-400 CVE-2021-32723: Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expre Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24. As a workaround, do not use ASCII
nvd
CVE-2021-26272MEDIUMCVSS 6.5fixed in 21.1.02021-01-26
CVE-2021-26272 [MEDIUM] CWE-829 CVE-2021-26272: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
nvd
CVE-2021-26271MEDIUMCVSS 6.5fixed in 21.1.02021-01-26
CVE-2021-26271 [MEDIUM] CWE-829 CVE-2021-26271: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
nvd