Vulnerabilities
Vulnerable Software
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.
CVSS Score
9.4
EPSS Score
0.006
Published
2026-04-08
A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.
CVSS Score
5.1
EPSS Score
0.004
Published
2026-04-08


Contact Us

Shodan ® - All rights reserved