Apache Struts vulnerabilities
90 known vulnerabilities affecting apache/struts.
Total CVEs
90
CISA KEV
8
actively exploited
Public exploits
37
Exploited in wild
19
Severity breakdown
CRITICAL22HIGH32MEDIUM35LOW1
Vulnerabilities
Page 5 of 5
CVE-2012-4386P4MEDIUMCVSS 6.8v2.0.0v2.0.1+33 more2012-09-05
CVE-2012-4386 [MEDIUM] CWE-352 CVE-2012-4386: The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token
The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
nvd
CVE-2016-4465P4MEDIUMCVSS 5.3v2.3.20v2.3.20.1+7 more2016-07-04
CVE-2016-4465 [MEDIUM] CWE-20 CVE-2016-4465: The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remo
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
nvd
CVE-2011-2088P4MEDIUMCVSS 5.0v2.2.12011-05-13
CVE-2011-2088 [MEDIUM] CVE-2011-2088: XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote at
XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
nvd
CVE-2008-2025P4MEDIUMCVSS 4.3v1.0.2v1.1+3 more2009-04-09
CVE-2008-2025 [MEDIUM] CWE-79 CVE-2008-2025: Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterp
Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insuffi
nvd
CVE-2012-4387P4MEDIUMCVSS 5.0v2.0.0v2.0.1+33 more2012-09-05
CVE-2012-4387 [MEDIUM] CWE-264 CVE-2012-4387: Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumpt
Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
nvd
CVE-2011-2087P4MEDIUMCVSS 4.3v2.0.0v2.0.1+26 more2011-05-13
CVE-2011-2087 [MEDIUM] CWE-79 CVE-2011-2087: Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka
Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenH
nvd
CVE-2013-6348P4MEDIUMCVSS 4.3v2.3.15.32013-11-02
CVE-2013-6348 [MEDIUM] CWE-79 CVE-2013-6348: Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/.
nvd
CVE-2008-6682P4MEDIUMCVSS 4.3v2.0.6v2.0.8+3 more2009-04-09
CVE-2008-6682 [MEDIUM] CWE-79 CVE-2008-6682: Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.
nvd
CVE-2006-1548P4MEDIUMCVSS 4.3≤ 1.2.82006-03-30
CVE-2006-1548 [MEDIUM] CVE-2006-1548: Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
nvd
CVE-2007-6726P4MEDIUMCVSS 4.3v2.0.92009-04-09
CVE-2007-6726 [MEDIUM] CWE-79 CVE-2007-6726: Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Strut
Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.
nvd
← Previous5 / 5