VendorsOWASPowasp_modsecurity_core_rule_setany version
Vulnerabilities

OWASP Owasp Modsecurity Core Rule Set any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2021-35368
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
Published 2021-11-05 · Modified
9.8EPSS 0.027
CVE-2022-39955
Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header
Published 2022-09-20 · Modified
9.8EPSS 0.014
CVE-2022-39956
Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encoding header
Published 2022-09-20 · Modified
9.8EPSS 0.012
CVE-2026-21876
OWASP CRS has multipart bypass using multiple content-type parts
Published 2026-01-08 · Modified
9.31 PoCEPSS 0.175
CVE-2018-16384
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed.
Published 2018-09-03 · Modified
7.5EPSS 0.017
CVE-2026-33691
OWASP CRS: Whitespace padding in filenames bypasses file upload extension checks
Published 2026-04-02 · Modified
7.5EPSS 0.016
CVE-2022-39958
Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte range
Published 2022-09-20 · Modified
7.5EPSS 0.012
CVE-2022-39957
Response body bypass in OWASP ModSecurity Core Rule Set via a specialy crafted charset in the HTTP Accept header
Published 2022-09-20 · Modified
7.5EPSS 0.010