CVE-2009-0026
Apache Jackrabbit <1.5.2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.
Exploits (2)
References (8)
Scores
EPSS
0.4010
EPSS Percentile
97.3%
Classification
CWE
CWE-79
Status
published
Affected Products (4)
apache/jackrabbit
apache/jackrabbit
org.apache.jackrabbit/jackrabbit
< 1.5.2Maven
n/a/n/a
Timeline
Published
Jan 21, 2009
Tracked Since
Feb 18, 2026