Apache / Struts
95 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-73632 | Apache Struts: Shared serialization state in the JSON plugin | MEDIUM | 4.3 | Aug 15, 2026 |
| CVE-2026-73631 | Apache Struts: Shared parsing state in the JSON plugin | MEDIUM | 4.3 | Aug 15, 2026 |
| CVE-2026-73635 | Apache Struts: Unbounded growth of localized-text caches driven by the request locale | HIGH | 7.5 | Aug 15, 2026 |
| CVE-2026-73634 | Apache Struts: Unbounded read of a Content Security Policy violation report | HIGH | 7.5 | Aug 15, 2026 |
| CVE-2026-73633 | Apache Struts: Unbounded read of a JSON request body | HIGH | 7.5 | Aug 14, 2026 |
| CVE-2025-68493 | Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component | HIGH | 8.1 | Jan 11, 2026 |
| CVE-2025-66675 | Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - version ranges fixed | HIGH | 8.2 | Dec 10, 2025 |
| CVE-2025-64775 | Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) | HIGH | 7.5 | Dec 1, 2025 |
| CVE-2024-53677 | Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks | CRITICAL | 9.5 | Dec 11, 2024 |
| CVE-2023-50164 | Apache Struts: File upload component had a directory traversal vulnerability | CRITICAL | 9.8 | Dec 7, 2023 |
| CVE-2023-41835 | Apache Struts: excessive disk usage | HIGH | 7.5 | Dec 5, 2023 |
| CVE-2023-34396 | Apache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart forms | HIGH | 7.5 | Jun 14, 2023 |
| CVE-2023-34149 | Apache Struts: DoS via OOM owing to not properly checking of list bounds | MEDIUM | 6.5 | Jun 14, 2023 |
| CVE-2021-31805 | Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE. | CRITICAL | 9.8 | Apr 12, 2022 |
| CVE-2020-26258 | Server-Side Forgery Request can be activated unmarshalling with XStream | HIGH | 7.7 | Dec 16, 2020 |
| CVE-2020-26259 | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling | MEDIUM | 6.8 | Dec 16, 2020 |
| CVE-2020-17530 KEV | struts2: using forced OGNL evaluation on untrusted user input can lead to a RCE and security degradation | CRITICAL | 9.8 | Dec 11, 2020 |
| CVE-2019-0233 | struts2: access permission override when performing a file upload leads to DoS | HIGH | 7.5 | Sep 14, 2020 |
| CVE-2019-0230 | struts2: possible RCE due to forced double OGNL evaluation when evaluated on raw user input in tag attributes | CRITICAL | 9.8 | Sep 14, 2020 |
| CVE-2015-2992 | struts: XSS vulnerability when JSP files are exposed to be accessed directly | MEDIUM | 6.1 | Feb 27, 2020 |
| CVE-2012-1592 | A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files. | HIGH | 8.8 | Dec 5, 2019 |
| CVE-2011-3923 | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. | CRITICAL | 9.8 | Nov 1, 2019 |
| CVE-2018-11776 KEV | struts2: Using specific results and namespaces can result in a remote code execution | HIGH | 8.1 | Aug 22, 2018 |
| CVE-2018-1327 | struts: Denial-of-Service attack via crafted XML request using Struts REST plugin | HIGH | 7.5 | Mar 27, 2018 |
| CVE-2017-15707 | struts2: Crafted JSON request can result in DoS | HIGH | 7.5 | Dec 1, 2017 |
Showing 1 to 25 of 95 CVEs