Apache / Shiro
25 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-58301 | Apache Shiro: Server-side POST request may be steered to an alternate host | MEDIUM | 5.9 | Aug 31, 2026 |
| CVE-2026-49268 | Apache Shiro: LDAP DN Injection in DefaultLdapRealm | HIGH | 8.8 | Jun 17, 2026 |
| CVE-2026-48589 | Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flow | LOW | 5.4 | May 25, 2026 |
| CVE-2026-44598 | Apache Shiro Jakarta EE module: Open redirect and SSRF (requires valid credentials) | MEDIUM | 5.1 | May 25, 2026 |
| CVE-2026-43828 | Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default | MEDIUM | 5.9 | May 25, 2026 |
| CVE-2026-43827 | Apache Shiro: Session fixation: new session is not created after login by default | MEDIUM | 5.9 | May 25, 2026 |
| CVE-2026-23901 | Apache Shiro: Brute force attack possible to determine valid user names | LOW | 1.0 | Feb 10, 2026 |
| CVE-2026-23903 | Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems | MEDIUM | 5.3 | Feb 9, 2026 |
| CVE-2023-46749 | Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with pat… | MEDIUM | 6.5 | Jan 15, 2024 |
| CVE-2023-46750 | Apache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro. | MEDIUM | 6.1 | Dec 14, 2023 |
| CVE-2023-34478 | Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route req… | CRITICAL | 9.3 | Jul 24, 2023 |
| CVE-2023-22602 | Apache Shiro before 1.11.0, when used with Spring Boot 2.6+, may allow authentication bypass through a specially crafted HTTP request | HIGH | 7.5 | Jan 14, 2023 |
| CVE-2022-40664 | Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher | CRITICAL | 9.8 | Oct 12, 2022 |
| CVE-2022-32532 | Authentication Bypass Vulnerability | CRITICAL | 9.8 | Jun 28, 2022 |
| CVE-2021-41303 | Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass | CRITICAL | 9.8 | Sep 17, 2021 |
| CVE-2020-17523 | shiro: Authentication bypass through specially crafted HTTP request | CRITICAL | 9.8 | Feb 3, 2021 |
| CVE-2020-17510 | shiro: specially crafted HTTP request may cause an authentication bypass | CRITICAL | 9.8 | Nov 5, 2020 |
| CVE-2020-13933 | shiro: specially crafted HTTP request may cause an authentication bypass | HIGH | 7.5 | Aug 17, 2020 |
| CVE-2020-11989 | shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass | CRITICAL | 9.8 | Jun 22, 2020 |
| CVE-2020-1957 | shiro: Spring dynamic controllers, a specially crafted request may cause an authentication bypass | CRITICAL | 9.8 | Mar 25, 2020 |
| CVE-2019-12422 | shiro: Cookie padding oracle vulnerability with default configuration | HIGH | 7.5 | Nov 18, 2019 |
| CVE-2016-6802 | Shiro: Security servlet filters bypass | HIGH | 7.5 | Sep 20, 2016 |
| CVE-2016-4437 KEV | shiro: Security constraint bypass | CRITICAL | 9.8 | Jun 7, 2016 |
| CVE-2014-0074 | Shiro: successful authentication without specifying user name or password | HIGH | 7.5 | Oct 6, 2014 |
| CVE-2010-3863 | Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote att… | MEDIUM | 5.0 | Nov 5, 2010 |
Showing 1 to 25 of 25 CVEs