Xapian is a search-engine library and toolkit that powers indexing and retrieval across applications and web platforms; its exposure concentrates in the Omega web search application and core library components, where the recurring weakness involves improper input neutralization leading to cross-site scripting vulnerabilities. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xapian over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0499MEDIUM A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). | Jul 2, 2018 | 6.1 | 22 | NO | NO |
CVE-2009-2947MEDIUM Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which ar | Sep 14, 2009 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xapian.
Media articles that mention a CVE ID that affects a product developed by Xapian — matched by CVE ID, not by vendor name.