Oracle Application Express vulnerabilities
47 known vulnerabilities affecting oracle/application_express.
Total CVEs
47
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL4HIGH2MEDIUM41
Vulnerabilities
Page 1 of 3
CVE-2020-11023P1MEDIUMCVSS 6.1KEVPoCfixed in 20.22020-04-29
CVE-2020-11023 [MEDIUM] CWE-79 CVE-2020-11023: In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option>
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2019-11358P2MEDIUMCVSS 6.1ExploitedPoCfixed in 19.12019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2025-50067P3CRITICALCVSS 9.0v24.2.4v24.2.52025-07-15
CVE-2025-50067 [CRITICAL] CWE-601 CVE-2025-50067: Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported v
Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other th
nvd
CVE-2021-41184P3MEDIUMCVSS 6.1fixed in 22.1.12021-10-26
CVE-2021-41184 [MEDIUM] CWE-79 CVE-2021-41184: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the val
nvd
CVE-2023-21974P3CRITICALCVSS 9.0≥ 18.2, ≤ 22.12023-07-18
CVE-2023-21974 [CRITICAL] CVE-2023-21974: Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express
Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Team Calendar Plugin: 18.2-22.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Team Calen
nvd
CVE-2021-41182P3MEDIUMCVSS 6.1fixed in 22.1.12021-10-26
CVE-2021-41182 [MEDIUM] CWE-79 CVE-2021-41182: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not acc
nvd
CVE-2023-21975P3CRITICALCVSS 9.0≥ 18.2, ≤ 22.22023-07-18
CVE-2023-21975 [CRITICAL] CVE-2023-21975: Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (com
Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Customers Plugin: 18.2-22.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Customers Plugin.
nvd
CVE-2022-24729P3HIGHCVSS 7.5fixed in 22.1.12022-03-16
CVE-2022-24729 [HIGH] CWE-400 CVE-2022-24729: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.1
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0.
nvd
CVE-2020-7760P3HIGHCVSS 7.5fixed in 20.22020-10-30
CVE-2020-7760 [HIGH] CWE-400 CVE-2020-7760: This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirro
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-patter
nvd
CVE-2016-7103P3MEDIUMCVSS 6.1fixed in 19.12017-03-15
CVE-2016-7103 [MEDIUM] CWE-79 CVE-2016-7103: Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
nvd
CVE-2021-41183P3MEDIUMCVSS 6.1fixed in 22.1.12021-10-26
CVE-2021-41183 [MEDIUM] CWE-79 CVE-2021-41183: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is
nvd
CVE-2008-1822P4CRITICALCVSS 10.0v3.0.12008-04-16
CVE-2008-1822 [CRITICAL] CVE-2008-1822: Unspecified vulnerability in the Oracle Application Express component in Oracle Application Express
Unspecified vulnerability in the Oracle Application Express component in Oracle Application Express 3.0.1 has unknown impact and remote attack vectors, aka APEX02.
nvd
CVE-2016-3467P4MEDIUMCVSS 5.8≤ 5.0.32016-07-21
CVE-2016-3467 [MEDIUM] CVE-2016-3467: Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0.
Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0.4 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2021-26272P4MEDIUMCVSS 6.5fixed in 21.1.02021-01-26
CVE-2021-26272 [MEDIUM] CWE-829 CVE-2021-26272: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
nvd
CVE-2023-21983P4MEDIUMCVSS 5.6≥ 18.2, ≤ 22.22023-07-18
CVE-2023-21983 [MEDIUM] CVE-2023-21983: Vulnerability in the Application Express Administration product of Oracle Application Express (compo
Vulnerability in the Application Express Administration product of Oracle Application Express (component: None). Supported versions that are affected are Application Express Administration: 18.2-22.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Express Administration. Successful a
nvd
CVE-2021-26271P4MEDIUMCVSS 6.5fixed in 21.1.02021-01-26
CVE-2021-26271 [MEDIUM] CWE-829 CVE-2021-26271: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
nvd
CVE-2016-3448P4MEDIUMCVSS 6.1≤ 5.0.32016-07-21
CVE-2016-3448 [MEDIUM] CVE-2016-3448: Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0.
Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0.4 allows remote attackers to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2020-26870P4MEDIUMCVSS 6.1fixed in 21.1.0.00.012020-10-07
CVE-2020-26870 [MEDIUM] CWE-79 CVE-2020-26870: Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
nvd
CVE-2020-9281P4MEDIUMCVSS 6.1fixed in 20.22020-03-07
CVE-2020-9281 [MEDIUM] CWE-79 CVE-2020-9281: A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 a
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
nvd
CVE-2021-32723P4MEDIUMCVSS 6.5fixed in 21.1.42021-06-28
CVE-2021-32723 [MEDIUM] CWE-400 CVE-2021-32723: Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expre
Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24. As a workaround, do not use ASC
nvd
1 / 3Next →