Maven package intelligence

org.apache.struts.xwork:xwork-core Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.apache.struts.xwork:xwork-core, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
2
Known exploited vulnerabilities affecting org.apache.struts.xwork:xwork-core
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
org.apache.struts.xwork:xwork-core KEVs with sensor-observed exploitation activity

Review org.apache.struts.xwork:xwork-core exploitation against the versions you run

One of the two exploited org.apache.struts.xwork:xwork-core vulnerabilities tracked here are not in CISA KEV.

50%
Covered by CISA
50%
Beyond CISA

Attested org.apache.struts.xwork:xwork-core vulnerabilities

2 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2025-68493

Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component

Beyond CISA 20 Jul 2026
CVE-2012-0391

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling...

In CISA 21 Jan 2022

Recurring weakness patterns

Missing XML Validation, Improper Restriction of XML External Entity Reference, and Improper Control of Generation of Code ('Code Injection') account for mapped occurrences across this org.apache.struts.xwork:xwork-core KEV portfolio.

Browse all KEVs →