VendorsApachestrutsany version
Vulnerabilities

Apache Struts any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

47CVEs
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
Published 2017-03-11 · Analyzed
10.0KEV2 PoCEPSS 1.000
CVE-2012-0838
Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.
Published 2012-03-02 · Modified
10.0EPSS 0.139
CVE-2013-2251
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
Published 2013-07-18 · Analyzed
9.8KEV2 PoCEPSS 1.000
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
Published 2020-09-14 · Modified
9.81 PoCEPSS 0.974
CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Published 2020-12-11 · Analyzed
9.8KEVEPSS 0.959
CVE-2011-3923
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
Published 2019-11-01 · Modified
9.81 PoCEPSS 0.895
CVE-2021-31805
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
Published 2022-04-12 · Modified
9.8EPSS 0.854
CVE-2023-50164
Apache Struts: File upload component had a directory traversal vulnerability
Published 2023-12-07 · Modified
9.8EPSS 0.808
CVE-2012-0391
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
Published 2012-01-08 · Analyzed
9.8KEV2 PoCEPSS 0.756
CVE-2024-53677
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
Published 2024-12-11 · Analyzed
9.8EPSS 0.701
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
Published 2018-08-22 · Analyzed
9.3KEV3 PoCEPSS 1.000
CVE-2013-1965
Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.
Published 2013-07-10 · Modified
9.3EPSS 0.935
CVE-2013-2115
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.
Published 2013-07-10 · Modified
9.31 PoCEPSS 0.746
CVE-2013-1966
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.
Published 2013-07-10 · Modified
9.31 PoCEPSS 0.737
CVE-2013-2134
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.
Published 2013-07-16 · Modified
9.31 PoCEPSS 0.702
CVE-2013-2135
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.
Published 2013-07-16 · Modified
9.3EPSS 0.138
CVE-2016-0785
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.
Published 2016-04-12 · Modified
9.0EPSS 0.089
CVE-2016-4461
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785.
Published 2017-10-16 · Modified
9.0EPSS 0.081
CVE-2025-66675
Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - version ranges fixed
Published 2025-12-10 · Analyzed
8.2EPSS 0.006
CVE-2017-9805
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Published 2017-09-15 · Analyzed
8.1KEV1 PoCEPSS 0.994
CVE-2025-68493
Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component
Published 2026-01-11 · Modified
8.1EPSS 0.433
CVE-2006-1547
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
Published 2006-03-30 · Analyzed
7.8KEVEPSS 0.546
CVE-2020-26258
Server-Side Forgery Request can be activated unmarshalling with XStream
Published 2020-12-16 · Analyzed
7.7EPSS 0.818
CVE-2014-0112
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
Published 2014-04-29 · Modified
7.52 PoCEPSS 0.979
CVE-2014-0113
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
Published 2014-04-29 · Modified
7.51 PoCEPSS 0.778
CVE-2019-0233
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Published 2020-09-14 · Modified
7.5EPSS 0.681
CVE-2018-1327
The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handler as described here http://struts.apache.org/plugins/rest/#custom-contenttypehandlers. Another option is to implement a custom XML handler based on the Jackson XML handler from the Apache Struts 2.5.16.
Published 2018-03-27 · Modified
7.5EPSS 0.086
CVE-2023-41835
Apache Struts: excessive disk usage
Published 2023-12-05 · Modified
7.5EPSS 0.073
CVE-2006-1546
Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
Published 2006-03-30 · Modified
7.5EPSS 0.063
CVE-2023-34396
Apache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart forms
Published 2023-06-14 · Modified
7.5EPSS 0.055
CVE-2025-64775
Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS)
Published 2025-12-01 · Analyzed
7.5EPSS 0.015
CVE-2026-73633
Apache Struts: Unbounded read of a JSON request body
Published 2026-08-14 · Analyzed
7.5EPSS 0.006
CVE-2026-73635
Apache Struts: Unbounded growth of localized-text caches driven by the request locale
Published 2026-08-15 · Analyzed
7.5EPSS 0.005
CVE-2026-73634
Apache Struts: Unbounded read of a Content Security Policy violation report
Published 2026-08-15 · Analyzed
7.5EPSS 0.004
CVE-2012-0392
The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.
Published 2012-01-08 · Modified
6.81 PoCEPSS 0.975
CVE-2020-26259
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling
Published 2020-12-16 · Analyzed
6.8EPSS 0.824
CVE-2012-0394
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself.
Published 2012-01-08 · Modified
6.82 PoCEPSS 0.729
CVE-2009-1275
Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.
Published 2009-04-09 · Modified
6.8EPSS 0.028
CVE-2023-34149
Apache Struts: DoS via OOM owing to not properly checking of list bounds
Published 2023-06-14 · Modified
6.5EPSS 0.054
CVE-2012-0393
The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.
Published 2012-01-08 · Modified
6.41 PoCEPSS 0.363
1 / 2Next →