Cocoon
Vendor:
First CVE: Dec 31, 2003 · Active for 22 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cocoon over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
Jan 27, 2025
543 days ago
CVE Severity & Scoring
Cocoon5 CVEs
20%
40%
40%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (80.0%)
Unknown1 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (80.0%)
High0 (0.0%)
Unknown1 (20.0%)
User Interaction
None4 (80.0%)
Unknown1 (20.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (80.0%)
Unknown1 (20.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11991HIGH When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server syst | Sep 11, 2020 | 7.5 | 74 | NO | YES |
CVE-2003-1172MEDIUM Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot do | Dec 31, 2003 | 5.0 | 37 | NO | YES |
CVE-2023-49733CRITICAL Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0.
Users are recommended to upgrade to | Nov 30, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-45135CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0.
User | Nov 30, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-24783HIGH ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon.
This issue affects Apache Cocoon: all versions.
| Jan 27, 2025 | 7.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
20.0% of CVEs· 98th percentile
ExploitDB
1 CVE
20.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Cocoon
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.2 | 1 | 5.0 | 30.8% | 0 | 1 |
| 2.1.2 | 1 | 5.0 | 30.8% | 0 | 1 |
| 2.1 | 1 | 5.0 | 30.8% | 0 | 1 |