cbcvebase.

Apache Struts vulnerabilities

95 known vulnerabilities affecting apache/struts.

Total CVEs
95
CISA KEV
8
actively exploited
Public exploits
38
Exploited in wild
19
Severity breakdown
CRITICAL22HIGH35MEDIUM37LOW1

Vulnerabilities

Page 5 of 5
CVE-2016-4465P4MEDIUMCVSS 5.3v2.3.20v2.3.20.1+7 more2016-07-04
CVE-2016-4465 [MEDIUM] CWE-20 CVE-2016-4465: The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remo The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
nvd
CVE-2016-2162P4MEDIUMCVSS 6.1v2.0.0v2.0.1+54 more2016-04-12
CVE-2016-2162 [MEDIUM] CWE-79 CVE-2016-2162: Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInter Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.
nvd
CVE-2015-2992P4MEDIUMCVSS 6.1≥ 2.0.0, < 2.3.202020-02-27
CVE-2015-2992 [MEDIUM] CWE-79 CVE-2015-2992: Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability. Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
nvd
CVE-2017-15707P4MEDIUMCVSS 6.2≥ 2.5, ≤ 2.5.142017-12-01
CVE-2017-15707 [MEDIUM] CWE-20 CVE-2017-15707: In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulne In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
nvd
CVE-2012-4386P4MEDIUMCVSS 6.8v2.0.0v2.0.1+33 more2012-09-05
CVE-2012-4386 [MEDIUM] CWE-352 CVE-2012-4386: The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
nvd
CVE-2011-2088P4MEDIUMCVSS 5.0v2.2.12011-05-13
CVE-2011-2088 [MEDIUM] CVE-2011-2088: XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote at XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.
nvd
CVE-2008-2025P4MEDIUMCVSS 4.3v1.0.2v1.1+3 more2009-04-09
CVE-2008-2025 [MEDIUM] CWE-79 CVE-2008-2025: Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterp Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insuffi
nvd
CVE-2012-4387P4MEDIUMCVSS 5.0v2.0.0v2.0.1+33 more2012-09-05
CVE-2012-4387 [MEDIUM] CWE-264 CVE-2012-4387: Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumpt Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
nvd
CVE-2026-73631P4MEDIUMCVSS 4.3v7.2.12026-08-15
CVE-2026-73631 [MEDIUM] CWE-567 CVE-2026-73631: Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-req Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be enforced as intended. Populating actions from a JSON request body is not
nvd
CVE-2026-73632P4MEDIUMCVSS 4.3v7.2.12026-08-15
CVE-2026-73632 [MEDIUM] CWE-567 CVE-2026-73632: Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-res Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by
nvd
CVE-2011-2087P4MEDIUMCVSS 4.3v2.0.0v2.0.1+26 more2011-05-13
CVE-2011-2087 [MEDIUM] CWE-79 CVE-2011-2087: Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenH
nvd
CVE-2013-6348P4MEDIUMCVSS 4.3v2.3.15.32013-11-02
CVE-2013-6348 [MEDIUM] CWE-79 CVE-2013-6348: Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/.
nvd
CVE-2008-6682P4MEDIUMCVSS 4.3v2.0.6v2.0.8+3 more2009-04-09
CVE-2008-6682 [MEDIUM] CWE-79 CVE-2008-6682: Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.
nvd
CVE-2006-1548P4MEDIUMCVSS 4.3≤ 1.2.82006-03-30
CVE-2006-1548 [MEDIUM] CVE-2006-1548: Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
nvd
CVE-2007-6726P4MEDIUMCVSS 4.3v2.0.92009-04-09
CVE-2007-6726 [MEDIUM] CWE-79 CVE-2007-6726: Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Strut Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.
nvd
Apache Struts vulnerabilities | cvebase