cbcvebase.

Oracle Application Express vulnerabilities

47 known vulnerabilities affecting oracle/application_express.

Total CVEs
47
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL4HIGH2MEDIUM41

Vulnerabilities

Page 2 of 3
CVE-2019-10219P4MEDIUMCVSS 6.1v21.1.42019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2008-1811P4MEDIUMCVSS 5.5v3.0.12008-04-16
CVE-2008-1811 [MEDIUM] CVE-2008-1811: Unspecified vulnerability in Oracle Application Express 3.0.1 has unspecified impact and remote auth Unspecified vulnerability in Oracle Application Express 3.0.1 has unspecified impact and remote authenticated attack vectors related to flows_030000.wwv_execute_immediate, aka APEX01. NOTE: the previous information was obtained from the April 2008 CPU. Oracle has not commented on reliable researcher claims that APEX01 is for insufficient authorization checks
nvd
CVE-2021-32809P4MEDIUMCVSS 5.4fixed in 21.1.42021-08-12
CVE-2021-32809 [MEDIUM] CWE-94 CVE-2021-32809: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all
nvd
CVE-2018-2699P4MEDIUMCVSS 6.1≤ 5.1.4.00.082018-01-18
CVE-2018-2699 [MEDIUM] CVE-2018-2699: Vulnerability in the Application Express component of Oracle Database Server. The supported version Vulnerability in the Application Express component of Oracle Database Server. The supported version that is affected is Prior to 5.1.4.00.08. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Express. Successful attacks require human interaction from a person other than the attacker and whil
nvd
CVE-2021-41165P4MEDIUMCVSS 5.4fixed in 22.12021-11-17
CVE-2021-41165 [MEDIUM] CWE-79 CVE-2021-41165: CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discov CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users usi
nvd
CVE-2021-32808P4MEDIUMCVSS 5.4fixed in 21.1.42021-08-12
CVE-2021-32808 [MEDIUM] CWE-79 CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been d ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEdit
nvd
CVE-2025-21557P4MEDIUMCVSS 5.4v23.2v24.12025-01-21
CVE-2025-21557 [MEDIUM] CWE-863 CVE-2025-21557: Vulnerability in Oracle Application Express (component: General). Supported versions that are affec Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while th
nvd
CVE-2024-21261P4MEDIUMCVSS 4.9v23.2v24.12024-10-15
CVE-2024-21261 [MEDIUM] CVE-2024-21261: Vulnerability in Oracle Application Express (component: General). Supported versions that are affec Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. While the vulnerability is in Oracle Application Express, attacks may significantly impact additional
nvd
CVE-2020-27193P4MEDIUMCVSS 6.1fixed in 21.1.0.00.012020-11-12
CVE-2020-27193 [MEDIUM] CWE-79 CVE-2020-27193: A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows rem A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
nvd
CVE-2021-37695P4MEDIUMCVSS 5.4fixed in 21.1.42021-08-13
CVE-2021-37695 [MEDIUM] CWE-79 CVE-2021-37695: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEdi
nvd
CVE-2021-41164P4MEDIUMCVSS 5.4fixed in 22.12021-11-17
CVE-2021-41164 [MEDIUM] CWE-79 CVE-2021-41164: CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been disco CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users us
nvd
CVE-2022-24728P4MEDIUMCVSS 5.4fixed in 22.1.12022-03-16
CVE-2022-24728 [MEDIUM] CWE-79 CVE-2022-24728: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been disco CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. T
nvd
CVE-2020-14763P4MEDIUMCVSS 5.4fixed in 20.22020-10-21
CVE-2020-14763 [MEDIUM] CVE-2020-14763: Vulnerability in the Oracle Application Express Quick Poll component of Oracle Database Server. The Vulnerability in the Oracle Application Express Quick Poll component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Quick Poll. Successful attacks requir
nvd
CVE-2020-14898P4MEDIUMCVSS 5.4fixed in 20.22020-10-21
CVE-2020-14898 [MEDIUM] CVE-2020-14898: Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server. T Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Packaged Apps. Successful attacks
nvd
CVE-2020-14762P4MEDIUMCVSS 5.4fixed in 20.22020-10-21
CVE-2020-14762 [MEDIUM] CVE-2020-14762: Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported v Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a
nvd
CVE-2020-14899P4MEDIUMCVSS 5.4fixed in 20.22020-10-21
CVE-2020-14899 [MEDIUM] CVE-2020-14899: Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. T Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Data Reporter. Successful attacks
nvd
CVE-2020-14900P4MEDIUMCVSS 5.4fixed in 20.22020-10-21
CVE-2020-14900 [MEDIUM] CVE-2020-14900: Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server. Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Group Calendar. Successful attack
nvd
CVE-2020-2971P4MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2971 [MEDIUM] CVE-2020-2971: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2975P4MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2975 [MEDIUM] CVE-2020-2975: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2974P4MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2974 [MEDIUM] CVE-2020-2974: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
Oracle Application Express vulnerabilities | cvebase