Every CVE whose affected-product data names Apache Sling Security, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (2)
CVE-2026-94243 — CVSS 7.3 (high): A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling…
CVE-2026-94251 — CVSS 6.5 (medium): A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue…