pkg:Maven/org.apache.struts:struts2-core
60 total CVEsCRITICAL14HIGH15MEDIUM8
✅ Check your installed version
All known vulnerabilities
- CRITICAL10.0CVE-2017-5638⚠ KEVApache Struts vulnerable to remote arbitrary command execution due to improper input validation>= 2.3.0, < 2.3.32
- from 0, < 2.3.15.1
- from 0, < 2.2.3.1
- >= 2.0.0, < 2.5.26
- HIGH8.1CVE-2018-11776⚠ KEVApache Struts vulnerable to remote command execution (RCE) due to improper input validation>= 2.0.4, < 2.3.35
- from 0, < 6.4.0
- >= 2.0.0, < 2.5.33
- from 0, < 2.3.20.3
- >= 2.0.0, < 2.3.29
- CRITICAL9.8CVE-2016-3087Apache Struts vulnerable to arbitrary remote code execution due to improper input validation>= 2.3.19, < 2.3.20.3
- >= 2.3.19, < 2.3.29
- >= 2.0.0, < 2.3.1.2
- >= 2.0.0, < 2.5.30
- CRITICAL9.8CVE-2019-0230Improperly Controlled Modification of Dynamically-Determined Object Attributes in Apache Struts>= 2.0.0, < 2.5.22
- CRITICAL9.8CVE-2017-12611Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal>= 2.0.1, < 2.3.34
- >= 2.0.0, < 2.3.29
- >= 2.0.0, < 2.3.20.3
- >= 2.0, < 2.5.22
- >= 2.0.0, < 6.8.0
- >= 2.0.0, <= 2.3.37
- >= 2.3.19, < 2.3.20.3
- >= 2.0.0, < 2.3.14.2
- >= 6.0.0, < 6.8.0
- HIGH7.5CVE-2023-41835Apache Struts Improper Control of Dynamically-Managed Code Resources vulnerability>= 6.2.0, < 6.3.0.1
- from 0, < 2.5.31
- >= 2.0.0, < 2.5.22
- from 0, < 2.3.24.1
- HIGH7.5CVE-2017-9804Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used>= 2.3.7, < 2.3.34
- >= 2.3.7, < 2.3.33
- from 0, < 2.5.31
- >= 2.0.0, < 2.3.28
- from 0, < 2.3.20
- >= 2.0.0, < 2.3.28
- >= 2.5.0, < 2.5.13
- >= 2.5.0, < 2.5.12
- >= 2.0.0, < 2.3.24.3
- >= 2.3.20, < 2.3.29
- from 0, < 2.3.20
- >= 2.0.0, < 2.0.11.1
- >= 2.0.0, < 2.0.12
- from 0, < 2.2.3
- from 0, < 2.3.16
- from 0, < 2.3.15.3
- >= 2.0.0, < 2.3.15.2
- from 0, < 2.3.15.1
- >= 2.0.0, < 2.3.4.1
- >= 2.0.0, < 2.3.20.1
- from 0, < 2.3.20
- >= 2.0.0, < 2.3.14.3
- >= 2.0.0, < 2.3.14.3
- from 0, < 2.2.3.1
- from 0, < 2.3.20
- from 0, < 2.3.14.3
- >= 2.0.0, < 2.3.14.2
- >= 2.0.0, < 2.3.16.2
- from 0, < 2.3.20
- from 0, < 2.3.20
- from 0, < 2.2.1
- from 0, < 2.2.3.1
- —CVE-2012-0393Apache Struts's ParameterInterceptor component does not prevent access to public constructorsfrom 0, < 2.3.1.1