📦 Struts

by Apache

🔍 What is Struts?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-53677

CRITICAL CVSS 9.8 Dec 11, 2024

This vulnerability in Apache Struts allows attackers to manipulate file upload parameters to perform path traversal attacks, potentially leading to remote code execution. It affects Apache Struts vers...

CVE-2023-50164

CRITICAL CVSS 9.8 Dec 7, 2023

This vulnerability in Apache Struts allows attackers to manipulate file upload parameters to perform path traversal attacks, potentially leading to remote code execution. It affects Apache Struts 2 in...

CVE-2021-31805

CRITICAL CVSS 9.8 Apr 12, 2022

This vulnerability in Apache Struts allows remote code execution when developers use forced OGNL evaluation (%{...} syntax) on untrusted user input. Attackers can exploit this to execute arbitrary cod...

CVE-2020-17530

CRITICAL CVSS 9.8 Dec 11, 2020

This vulnerability in Apache Struts allows attackers to perform remote code execution by forcing OGNL evaluation on raw user input in tag attributes. It affects all Apache Struts 2 installations from ...

CVE-2025-68493

HIGH CVSS 8.1 Jan 11, 2026

This CVE describes a Missing XML Validation vulnerability in Apache Struts that allows attackers to inject malicious XML content. It affects Apache Struts versions from 2.0.0 through 6.1.0, potentiall...

CVE-2025-66675

HIGH CVSS 8.2 Dec 10, 2025

This CVE describes a Denial of Service vulnerability in Apache Struts where specially crafted multipart requests can cause file leaks leading to disk exhaustion. Attackers can exploit this to fill up ...

CVE-2025-64775

HIGH CVSS 7.5 Dec 1, 2025

This vulnerability in Apache Struts allows attackers to cause a denial of service through disk exhaustion by exploiting a file leak in multipart request processing. It affects all Apache Struts instal...