Maven package intelligence
org.apache.struts:struts2-core Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the Maven package org.apache.struts:struts2-core, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 9
- Known exploited vulnerabilities affecting org.apache.struts:struts2-core
- In CISA KEV
- 5
- Records also listed in the official catalog
- Beyond CISA KEV
- 4
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 3
- org.apache.struts:struts2-core KEVs with sensor-observed exploitation activity
Review org.apache.struts:struts2-core exploitation against the versions you run
Four of the nine exploited org.apache.struts:struts2-core vulnerabilities tracked here are not in CISA KEV.
- 56%
- Covered by CISA
- 44%
- Beyond CISA
Attested org.apache.struts:struts2-core vulnerabilities
9 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2016-3081
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to... |
Beyond CISA | 23 Jul 2026 |
|
CVE-2025-68493
Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component |
Beyond CISA | 20 Jul 2026 |
|
CVE-2021-31805
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE. |
Beyond CISA | 12 Jun 2026 |
|
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by... |
In CISA | 03 Nov 2021 |
|
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message... |
In CISA | 03 Nov 2021 |
|
CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts... |
In CISA | 03 Nov 2021 |
|
CVE-2012-0391
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling... |
In CISA | 21 Jan 2022 |
|
CVE-2013-2251
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2)... |
In CISA | 25 Mar 2022 |
|
CVE-2024-53677
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks |
Beyond CISA | 11 Dec 2024 |
Recurring weakness patterns
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection'), Unrestricted Upload of File with Dangerous Type, and Improper Restriction of XML External Entity Reference account for mapped occurrences across this org.apache.struts:struts2-core KEV portfolio.
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CWE-434
Unrestricted Upload of File with Dangerous Type
CWE-611
Improper Restriction of XML External Entity Reference
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-755
Improper Handling of Exceptional Conditions
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-112
Missing XML Validation
CWE-94
Improper Control of Generation of Code ('Code Injection')