CVE-2026-40023
Medium Severity
Description
Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize charact...
Related Vulnerabilities
- CVE-2026-34477: The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: i MEDIUM
- CVE-2026-34486: Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-2914 MEDIUM
- CVE-2026-4432: The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist own HIGH
- CVE-2025-70797: Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execut MEDIUM
- CVE-2026-5477: An integer overflow existed in the wolfCrypt CMAC implementation, that could be exploited to forge C HIGH
Related Coverage
Threat Actors