Skip to main content

Vendor/product archive

trustwave / modsecurity CVEs

Beta · best-effort

14 CVEs tagged to trustwave / modsecurity0 Critical, 7 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2025-47947

Published May 21, 2025

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of servi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27110

Published Feb 25, 2025

Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46292

Published Oct 9, 2024

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Su…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5705

Published Apr 15, 2014

apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encodin…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5031

Published Jul 22, 2012

ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1903

Published Jun 3, 2009

The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1