← Back

Shiro

shiro

Vendor: Apache • 24 CVEs

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Shiro
May 6, 2026
Sep 20, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
2Apache
Redhat
4Aurora
FuseJboss Middleware Text Only Advisories+1 more
Apr 22, 2026
Jun 7, 2016
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request para...Show more
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.Show less
1Apache
1Shiro
May 6, 2026
Oct 6, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.
2Apache
Jsecurity
2Jsecurity
Shiro
Apr 29, 2026
Nov 5, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted r...Show more
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.Show less