Maven package intelligence

org.apache.struts:struts2-core Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.apache.struts:struts2-core, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
9
Known exploited vulnerabilities affecting org.apache.struts:struts2-core
In CISA KEV
5
Records also listed in the official catalog
Beyond CISA KEV
4
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
3
org.apache.struts:struts2-core KEVs with sensor-observed exploitation activity

Review org.apache.struts:struts2-core exploitation against the versions you run

Four of the nine exploited org.apache.struts:struts2-core vulnerabilities tracked here are not in CISA KEV.

56%
Covered by CISA
44%
Beyond CISA

Attested org.apache.struts:struts2-core vulnerabilities

9 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2016-3081

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to...

Beyond CISA 23 Jul 2026
CVE-2025-68493

Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component

Beyond CISA 20 Jul 2026
CVE-2021-31805

Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.

Beyond CISA 12 Jun 2026
CVE-2018-11776

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by...

In CISA 03 Nov 2021
CVE-2017-5638

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message...

In CISA 03 Nov 2021
CVE-2020-17530

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts...

In CISA 03 Nov 2021
CVE-2012-0391

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling...

In CISA 21 Jan 2022
CVE-2013-2251

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2)...

In CISA 25 Mar 2022
CVE-2024-53677

Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks

Beyond CISA 11 Dec 2024

Recurring weakness patterns

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection'), Unrestricted Upload of File with Dangerous Type, and Improper Restriction of XML External Entity Reference account for mapped occurrences across this org.apache.struts:struts2-core KEV portfolio.

Browse all KEVs →