PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Network Vulnerabilities·Updated Jul 14, 2026

Apache Tomcat - Cross-Site Scripting

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-50229
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Apache Tomcatby Apache Software Foundation
11.0.0-M1
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Apache Tomcat - Cross-Site Scripting CVE-2026-50229 Scanner | S4E