Skip to main content

Vendor/product archive

owasp / modsecurity CVEs

Beta · best-effort

15 CVEs tagged to owasp / modsecurity0 Critical, 11 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-52761

Published Jul 10, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src…

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-52747

Published Jul 10, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libm…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-42268

Published May 12, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::o…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30923

Published May 5, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project. A seg…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-54571

Published Aug 6, 2025

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can override the HTTP resp…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48866

Published Jun 2, 2025

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1019

Published Jan 30, 2024

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encod…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28882

Published Apr 28, 2023

Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a segfault in the Transaction class…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-25043

Published May 6, 2021

ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15598

Published Oct 6, 2020

Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are disputing our claims." The CV…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19886

Published Jan 21, 2020

Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsiv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-13065

Published Jul 3, 2018

ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1