Apache ActiveMQ and ActiveMQ Web Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Apache ActiveMQ and Apache ActiveMQ Web. This issue allows authenticated attackers to inject malicious HTML content into a JMS selector field, which is then rendered in the web console. The vulnerability arises from improper handling of script-related HTML tags, enabling the injection of HTML when the content type is incorrectly set to HTML instead of XML. This issue affects Apache ActiveMQ versions prior to 5.19.6 and 6.0.0 versions prior to 6.2.5, as well as Apache ActiveMQ Web versions prior to 5.19.6 and 6.0.0 versions prior to 6.2.5.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected HTML is executed in the context of the user's browser.

Remediation

Users are advised to upgrade to Apache ActiveMQ version 6.2.5 or 5.19.6, both of which address this vulnerability. For Apache ActiveMQ Web, the same version recommendations apply.

Added: Apr 24, 2026, 11:23 AM
Updated: Apr 24, 2026, 11:23 AM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
1.7
exploitability
4.9
remediation
7.7
relevance
6.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.