Skip to main content

Vendor/product archive

owasp / owasp_modsecurity_core_rule_set CVEs

Beta · best-effort

9 CVEs tagged to owasp / owasp_modsecurity_core_rule_set3 Critical, 5 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-33691

Published Apr 2, 2026

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identi…

CVSS 6.8 · Medium
evidence mentions
11
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-21876

Published Jan 8, 2026

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 92…

CVSS 9.3 · Critical
evidence mentions
10
Buzz score
40.5
Vendor/product tagsBeta · best-effort

CVE-2018-16384

Published Sep 3, 2018

A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1