{"id":"CVE-2016-6810","aliases":["GHSA-5jg4-p78r-p5j3"],"url":"https://o3.security/vulnerability/CVE-2016-6810","summary":"Improper Neutralization of Input During Web Page Generation Apache ActiveMQ","details":"In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.","published":"2018-01-10T15:29:00.190Z","modified":"2026-07-08T10:53:33.294586Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.06093,"percentile":0.92802,"asOf":"2026-08-18"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.activemq:activemq-client","fixedVersion":"5.14.2"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/924a3a27fad192d711436421e02977ff90d9fc0f298e1efe6757cfbc%40%3Cusers.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E"},{"type":"ADVISORY","url":"http://activemq.apache.org/security-advisories.data/CVE-2016-6810-announcement.txt"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/94882"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1037475"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T10:53:33.294586Z"}}