CVE-2020-1949: Apache Sling CMS
Medium severity, CVSS 6.1. EPSS: 2% chance of exploitation in the next 30 days.
Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.
Affected products
- Apache Sling CMS: before 0.16.0 (fixed in 0.16.0)
Published 2020-04-01. Last modified 2026-06-17.