Known vulnerabilities in Apache POI
Vendor:
Apache Foundation
Software:
Apache POI
Software CPE:
cpe:2.3:a:apache_foundation:poi-scratchpad:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
6.0.0
5.5.1
5.5.0
5.4.2
5.4.1
5.4.0
5.3.1
5.3.0
5.2.6
5.2.5
5.2.4
5.2.3
5.2.2
5.2.1
5.2.0
5.1.0
5.0.1
5.0.0
4.1.3
4.1.2
4.1.1
4.1.0
4.0.1
4.0.0
3.9
3.7
3.6
1.5.1
1.5
1.2.0
1.1.0
1.0.2
1.0.1
1.0.0
0.14.0
0.13.0
0.12.0
0.11.0
0.10.0
0.6
0.5
0.4
0.3
0.2
0.1
3.11-20141221
3.10.1
3.11
3.12
3.13
3.14
3.15
3.16
3.17
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU112257 - Improper input validation CVE-2025-31672 |
CWE-20 | Medium | 5.4.0 | 04.07.2025 |
SB20250704104 SB2025070708 SB2025071664 and 23 more |
||
| #VU61043 - Resource Management Errors CVE-2022-26336 |
CWE-399 | Medium | 5.2.1 | 07.03.2022 |
SB2022030703 SB2023012211 SB2023020762 and 6 more |
||
| #VU22545 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2019-12415 |
CWE-611 | High | 4.1.1 | 06.11.2019 |
SB2019110635 SB2020012308 SB2020012309 and 42 more |