CVE-2016-6810: Apache ActiveMQ

Medium severity, CVSS 6.1. EPSS: 6.1% chance of exploitation in the next 30 days.

In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.

Affected products

  • Apache ActiveMQ: from 5.0.0, before 5.14.2 (fixed in 5.14.2)

Published 2018-01-10. Last modified 2026-06-17.