Skip to main content

Vendor/product archive

apache / struts CVEs

Beta · best-effort

91 CVEs tagged to apache / struts22 Critical, 30 High, 38 Medium, 1 Low, 0 Unrated.

CVE-2025-68493

Published Jan 11, 2026

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users a…

CVSS 8.1 · High
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2025-66675

Published Dec 10, 2025

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, fr…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64775

Published Dec 1, 2025

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, fr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53677

Published Dec 11, 2024

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a mal…

CVSS 9.5 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2023-50164

Published Dec 7, 2023

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remot…

CVSS 9.8 · Critical
evidence mentions
12
Buzz score
33.6
Vendor/product tagsBeta · best-effort

CVE-2023-41835

Published Dec 5, 2023

When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34396

Published Jun 14, 2023

Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Up…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34149

Published Jun 14, 2023

Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Up…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31805

Published Apr 12, 2022

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applie…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2020-17530

Published Dec 11, 2020

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
60.3
KEV listed

CVE-2015-2992

Published Feb 27, 2020

Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1592

Published Dec 5, 2019

A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11776

Published Aug 22, 2018

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Conventio…

CVSS 8.1 · High
evidence mentions
22
Buzz score
68.0
KEV listed

CVE-2018-1327

Published Mar 27, 2018

The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrad…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-3090

Published Oct 30, 2017

The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4461

Published Oct 16, 2017

Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerabi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5169

Published Sep 25, 2017

Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9804

Published Sep 20, 2017

In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2017-9793

Published Sep 20, 2017

The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using m…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort
Showing 1-25 of 91 CVEsPage 1 of 4