VYPR

Shindig

by Apache

CVEs (2)

  • CVE-2026-66256HigAug 13, 2026
    risk 0.47cvss 7.2epss

    ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. …

  • CVE-2013-4295Oct 24, 2013
    risk 0.04cvss epss 0.12

    The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.