VendorsOWASPowasp_modsecurity_core_rule_setall versions
Vulnerabilities

OWASP Owasp Modsecurity Core Rule Set

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2021-35368
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
Published 2021-11-05 · Modified
9.8EPSS 0.027
CVE-2022-39955
Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header
Published 2022-09-20 · Modified
9.8EPSS 0.014
CVE-2020-22669
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
Published 2022-09-02 · Modified
9.8EPSS 0.013
CVE-2022-39956
Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encoding header
Published 2022-09-20 · Modified
9.8EPSS 0.012
CVE-2026-21876
OWASP CRS has multipart bypass using multiple content-type parts
Published 2026-01-08 · Modified
9.31 PoCEPSS 0.175
CVE-2026-33691
OWASP CRS: Whitespace padding in filenames bypasses file upload extension checks
Published 2026-04-02 · Modified
7.5EPSS 0.036
CVE-2018-16384
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed.
Published 2018-09-03 · Modified
7.5EPSS 0.017
CVE-2022-39958
Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte range
Published 2022-09-20 · Modified
7.5EPSS 0.012
CVE-2022-39957
Response body bypass in OWASP ModSecurity Core Rule Set via a specialy crafted charset in the HTTP Accept header
Published 2022-09-20 · Modified
7.5EPSS 0.010