VYPR

Nexus Repository

by Sonatype

CVEs (27)

  • CVE-2025-13488MedDec 4, 2025
    risk 0.33cvss —epss 0.00

    Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS)…

  • CVE-2024-5083MedNov 14, 2024
    risk 0.33cvss —epss 0.00

    A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

  • CVE-2020-24622MedAug 25, 2020
    risk 0.32cvss 4.9epss 0.01

    In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.

  • CVE-2022-27907MedMar 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.

  • CVE-2021-43961MedMar 17, 2022
    risk 0.28cvss 4.3epss 0.01

    Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.

  • CVE-2026-17597LowAug 7, 2026
    risk 0.18cvss 2.7epss 0.00

    Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the…

  • CVE-2026-17595LowAug 7, 2026
    risk 0.18cvss 2.7epss 0.00

    Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal…

Page 2 of 2