org.dspace:dspace-api
DSpace core data model and service APIs.
Security Advisories for org.dspace:dspace-api in maven
Moderate
11 months ago
DSpace is vulnerable to Path Traversal attacks when importing packages using Simple Archive Format
maven
org.dspace:dspace-api
Moderate
11 months ago
DSpace is vulnerable to XML External Entity injection during archive imports
maven
org.dspace:dspace-api
Potential
Low
almost 2 years ago
DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document
maven
org.dspace:dspace-server-webapp
High
almost 4 years ago
DSpace ItemImportService API Vulnerable to Path Traversal in Simple Archive Format Package Import
maven
org.dspace:dspace-api
Potential
High
almost 4 years ago
JSPUI vulnerable to path traversal in submission (resumable) upload
maven
org.dspace:dspace-jspui
Potential
High
almost 4 years ago
JSPUI's controlled vocabulary feature vulnerable to Open Redirect before v6.4 and v5.11
maven
org.dspace:dspace-jspui
Potential
High
almost 4 years ago
JSPUI Possible Cross Site Scripting in "Request a Copy" Feature
maven
org.dspace:dspace-jspui
Potential
High
almost 4 years ago
JSPUI spellcheck and autocomplete tools vulnerable to Cross Site Scripting
maven
org.dspace:dspace-jspui
Potential
Moderate
almost 4 years ago
XMLUI's metadata of withdrawn Items is exposed to anonymous users
maven
org.dspace:dspace-xmlui
Potential
Moderate
almost 4 years ago
JSPUI's "Internal System Error" page prints exceptions and stack traces without sanitization
maven
org.dspace:dspace-jspui
High
over 4 years ago
Communities and collections administrators can escalate their privilege up to system administrator
maven
org.dspace:dspace-api
Potential
High
over 7 years ago
High severity vulnerability that affects org.dspace:dspace-xmlui
maven
org.dspace:dspace-xmlui