← Back

Struts

struts

Vendor: Apache • 90 CVEs

CVEs (90)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Struts
May 6, 2026
Jul 4, 2016
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service vi...Show more
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.Show less
2Apache
Oracle
3Banking Platform
PortalStruts
May 6, 2026
Jul 4, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory...Show more
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.Show less
1Apache
1Struts
May 6, 2026
Jul 4, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.
2Apache
Ognl Project
2Ognl
Struts
May 6, 2026
Jun 7, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified ve...Show more
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.Show less
1Apache
1Struts
May 6, 2026
Jun 7, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) opera...Show more
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.Show less
1Apache
1Struts
May 6, 2026
Apr 26, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
2Apache
Oracle
2Siebel E Billing
Struts
May 6, 2026
Apr 26, 2016
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
1Apache
1Struts
May 6, 2026
Apr 12, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web s...Show more
Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter.Show less
1Apache
1Struts
May 6, 2026
Apr 12, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involvi...Show more
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.Show less
1Apache
1Struts
May 6, 2026
Apr 12, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.
1Apache
1Struts
May 6, 2026
Jul 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors.
1Apache
1Struts
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mechanism.
1Apache
1Struts
May 6, 2026
May 8, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and...Show more
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.Show less
1Apache
2Commons Beanutils
Struts
May 6, 2026
Apr 30, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which...Show more
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.Show less
1Apache
1Struts
May 6, 2026
Apr 29, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and exe...Show more
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.Show less
1Apache
1Struts
May 6, 2026
Apr 29, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted reques...Show more
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.Show less
1Apache
1Struts
May 6, 2026
Mar 11, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
1Apache
1Struts
Apr 29, 2026
Nov 2, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/.Show less
2Apache
Oracle
4Flexcube Private Banking
Mysql Enterprise MonitorStruts+1 more
Apr 29, 2026
Sep 30, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
1Apache
1Struts
Apr 29, 2026
Sep 30, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.