Apache Struts vulnerabilities
95 known vulnerabilities affecting apache/struts.
Total CVEs
95
CISA KEV
8
actively exploited
Public exploits
38
Exploited in wild
19
Severity breakdown
CRITICAL22HIGH35MEDIUM37LOW1
Vulnerabilities
Page 5 of 5
CVE-2016-4465P4MEDIUMCVSS 5.3v2.3.20v2.3.20.1+7 more2016-07-04
CVE-2016-4465 [MEDIUM] CWE-20 CVE-2016-4465: The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remo
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
nvd
CVE-2016-2162P4MEDIUMCVSS 6.1v2.0.0v2.0.1+54 more2016-04-12
CVE-2016-2162 [MEDIUM] CWE-79 CVE-2016-2162: Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInter
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.
nvd
CVE-2015-2992P4MEDIUMCVSS 6.1≥ 2.0.0, < 2.3.202020-02-27
CVE-2015-2992 [MEDIUM] CWE-79 CVE-2015-2992: Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
nvd
CVE-2017-15707P4MEDIUMCVSS 6.2≥ 2.5, ≤ 2.5.142017-12-01
CVE-2017-15707 [MEDIUM] CWE-20 CVE-2017-15707: In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulne
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
nvd
CVE-2012-4386P4MEDIUMCVSS 6.8v2.0.0v2.0.1+33 more2012-09-05
CVE-2012-4386 [MEDIUM] CWE-352 CVE-2012-4386: The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token
The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
nvd
CVE-2011-2088P4MEDIUMCVSS 5.0v2.2.12011-05-13
CVE-2011-2088 [MEDIUM] CVE-2011-2088: XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote at
XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
nvd
CVE-2008-2025P4MEDIUMCVSS 4.3v1.0.2v1.1+3 more2009-04-09
CVE-2008-2025 [MEDIUM] CWE-79 CVE-2008-2025: Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterp
Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insuffi
nvd
CVE-2012-4387P4MEDIUMCVSS 5.0v2.0.0v2.0.1+33 more2012-09-05
CVE-2012-4387 [MEDIUM] CWE-264 CVE-2012-4387: Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumpt
Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
nvd
CVE-2026-73631P4MEDIUMCVSS 4.3v7.2.12026-08-15
CVE-2026-73631 [MEDIUM] CWE-567 CVE-2026-73631: Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-req
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be enforced as intended. Populating actions from a JSON request body is not
nvd
CVE-2026-73632P4MEDIUMCVSS 4.3v7.2.12026-08-15
CVE-2026-73632 [MEDIUM] CWE-567 CVE-2026-73632: Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-res
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by
nvd
CVE-2011-2087P4MEDIUMCVSS 4.3v2.0.0v2.0.1+26 more2011-05-13
CVE-2011-2087 [MEDIUM] CWE-79 CVE-2011-2087: Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka
Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenH
nvd
CVE-2013-6348P4MEDIUMCVSS 4.3v2.3.15.32013-11-02
CVE-2013-6348 [MEDIUM] CWE-79 CVE-2013-6348: Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/.
nvd
CVE-2008-6682P4MEDIUMCVSS 4.3v2.0.6v2.0.8+3 more2009-04-09
CVE-2008-6682 [MEDIUM] CWE-79 CVE-2008-6682: Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.
nvd
CVE-2006-1548P4MEDIUMCVSS 4.3≤ 1.2.82006-03-30
CVE-2006-1548 [MEDIUM] CVE-2006-1548: Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
nvd
CVE-2007-6726P4MEDIUMCVSS 4.3v2.0.92009-04-09
CVE-2007-6726 [MEDIUM] CWE-79 CVE-2007-6726: Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Strut
Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.
nvd
← Previous5 / 5