FLAT-MTI33 (CVE-2025-68493)
Insecure functionality In org.apache.struts:struts2-core
6.8
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-54AB9 (CVE-2025-66675)
Insecure session management In org.apache.struts:struts2-core
6.7
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-369CM (CVE-2025-64775)
Technical information leak In org.apache.struts:struts2-core
2.7
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-DHAXK (CVE-2025-54656)
Log injection In struts:struts
2.7
Low
Ecosystem: Maven
Component: struts:struts
FLAT-DGOKK (CVE-2024-53677)
Insecure file upload In org.apache.struts:struts2-core
8.4
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-SVHVB (CVE-2023-50164)
Local file inclusion In org.apache.struts:struts2-core
8.1
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-D5W44 (CVE-2023-41835)
Insecurely deleted files In org.apache.struts:struts2-core
6.6
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-0LXSB (CVE-2023-34149)
Inadequate file size control In org.apache.struts:struts2-core
4.9
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-W2782 (CVE-2023-34396)
Inadequate file size control In org.apache.struts:struts-core
4.9
Medium
Ecosystem: Maven
Component: org.apache.struts:struts-core
FLAT-4UL80 (CVE-2019-0233)
Excessive privileges In org.apache.struts:struts2-core
6.6
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-OAD99 (CVE-2015-2992)
Reflected cross-site scripting (XSS) In org.apache.struts:struts2-core
0.6
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-QFH6O (CVE-2008-6682)
Reflected cross-site scripting (XSS) In org.apache.struts:struts2-core
1.3
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-4Z8FL (CVE-2008-6505)
Lack of data validation - Path Traversal In org.apache.struts:struts2-core
2.7
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-P3NAR (CVE-2011-2087)
Reflected cross-site scripting (XSS) In org.apache.struts:struts2-parent
1.3
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-parent
FLAT-PXKRL (CVE-2011-1772)
Reflected cross-site scripting (XSS) In org.apache.struts:struts2-core
1.2
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-9S71C (CVE-2013-6348)
Reflected cross-site scripting (XSS) In org.apache.struts:struts2-core
1.3
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-C1K24 (CVE-2013-4310)
Improper authorization control for web services In org.apache.struts:struts2-core
2.7
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-05LV3 (CVE-2016-2162)
Reflected cross-site scripting (XSS) In org.apache.struts:struts2-core
1.3
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-ZBANY (CVE-2016-3082)
Lack of data validation In org.apache.struts:struts2-core
8.1
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-LQJHD (CVE-2013-4316)
Server side template injection In org.apache.struts:struts2-rest-plugin
2.7
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-rest-plugin
FLAT-SMWI8 (CVE-2013-2248)
Lack of data validation In org.apache.struts:struts2-core
1.3
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-ASHJT (CVE-2016-4436)
Lack of data validation In org.apache.struts:struts2-core
8.1
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-PMRJJ (CVE-2016-4465)
Lack of data validation In org.apache.struts:struts2-core
2.7
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-EG0QX (CVE-2016-4431)
Lack of data validation In org.apache.struts:struts-parent
6.6
Medium
Ecosystem: Maven
Component: org.apache.struts:struts-parent
FLAT-3656M (CVE-2012-1006)
Reflected cross-site scripting (XSS) In org.apache.struts:struts2-parent
1.3
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-parent
FLAT-TOY1B (CVE-2012-4386)
Cross-site request forgery In org.apache.struts:struts2-core
1.3
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-IYMKC (CVE-2015-1831)
Security controls bypass or absence In org.apache.struts:struts2-core
2.7
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-TU9XU (CVE-2015-0899)
Lack of data validation In org.apache.struts:struts-core
6.6
Medium
Ecosystem: Maven
Component: org.apache.struts:struts-core
FLAT-4VZSJ (CVE-2015-5209)
Lack of data validation In org.apache.struts:struts2-core
6.6
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-TJZIU (CVE-2016-3090)
Lack of data validation In org.apache.struts:struts2-parent
6.3
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-parent
FLAT-S39QI (CVE-2016-8738)
Lack of data validation In org.apache.struts:struts2-core
4.6
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-TEJ4Y (CVE-2014-7809)
Cross-site request forgery In org.apache.struts:struts2-core
0.6
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-O8XJ7 (CVE-2012-1007)
Reflected cross-site scripting (XSS) In struts:struts
1.2
Low
Ecosystem: Maven
Component: struts:struts
FLAT-W5JA8 (CVE-2013-2134)
Server side template injection In org.apache.struts:struts2-core
2.7
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-B6MYB (CVE-2015-5169)
Reflected cross-site scripting (XSS) In org.apache.struts:struts2-core
1.3
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-NBTCI (CVE-2016-4003)
Reflected cross-site scripting (XSS) In org.apache.struts:struts2-core
1.3
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-HV8EZ (CVE-2016-4461)
Lack of data validation In org.apache.struts:struts2-core
6.3
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-B5XFW (CVE-2014-0112)
Remote command execution In org.apache.struts:struts2-core
8.1
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-CGX4K (CVE-2014-0094)
Remote command execution In org.apache.struts:struts2-core
9.1
Critical
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-N55LY (CVE-2014-0113)
Security controls bypass or absence In org.apache.struts:struts2-core
2.7
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-UQ2OF (CVE-2013-1965)
Server side template injection In org.apache.struts:struts2-core
2.7
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-CBRLQ (CVE-2014-0116)
Security controls bypass or absence In org.apache.struts:struts2-core
2.7
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-D3NWZ (CVE-2016-3081)
Server side template injection In org.apache.struts:struts2-core
7.2
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-BDT56 (CVE-2016-3087)
Lack of data validation In org.apache.struts:struts2-core
8.1
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-INYSH (CVE-2016-4438)
Lack of data validation In org.apache.struts:struts2-core
8.1
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-HVX7X (CVE-2016-6795)
Lack of data validation - Path Traversal In org.apache.struts:struts2-convention-plugin
8.1
High
Ecosystem: Maven
Component: org.apache.struts:struts2-convention-plugin
FLAT-ZJX13 (CVE-2016-0785)
Lack of data validation In org.apache.struts:struts2-core
6.3
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-P34VM (CVE-2017-9791)
Lack of data validation In org.apache.struts:struts2-struts1-plugin
8.1
High
Ecosystem: Maven
Component: org.apache.struts:struts2-struts1-plugin
FLAT-BQSYR (CVE-2016-1181)
Lack of data validation In org.apache.struts:struts-core
7.2
High
Ecosystem: Maven
Component: org.apache.struts:struts-core
FLAT-4E9Z8 (CVE-2016-1182)
Lack of data validation In struts:struts
6.7
Medium
Ecosystem: Maven
Component: struts:struts
FLAT-CF8DM (CVE-2013-2115)
Server side template injection In org.apache.struts:struts2-core
7.2
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-846C7 (CVE-2010-1870)
Server side template injection In org.apache.struts:struts2-core
2.7
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-Y657F (CVE-2013-2251)
Lack of data validation In org.apache.struts:struts2-core
1.3
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-H83LL (CVE-2012-0392)
Insecure service configuration In org.apache.struts:struts2-core
0.6
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-SB3UC (CVE-2008-2025)
Reflected cross-site scripting (XSS) In struts:struts
1.3
Low
Ecosystem: Maven
Component: struts:struts
FLAT-8JZ1H (CVE-2007-6726)
Reflected cross-site scripting (XSS) In org.apache.struts:struts2-dojo-plugin
1.3
Low
Ecosystem: Maven
Component: org.apache.struts:struts2-dojo-plugin
FLAT-HPUL7 (CVE-2006-1547)
Lack of data validation In struts:struts
6.6
Medium
Ecosystem: Maven
Component: struts:struts
FLAT-8C11W (CVE-2006-1548)
Reflected cross-site scripting (XSS) In struts:struts
1.7
Low
Ecosystem: Maven
Component: struts:struts
FLAT-Y913R (CVE-2006-1546)
Lack of data validation In struts:struts
2.7
Low
Ecosystem: Maven
Component: struts:struts
FLAT-1TIRT (CVE-2005-3745)
Lack of data validation - Path Traversal In org.apache.struts:struts-core
1.3
Low
Ecosystem: Maven
Component: org.apache.struts:struts-core
FLAT-L704V (CVE-2012-1592)
Insecure file upload In org.apache.struts:struts2-core
6.3
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-L9Q33 (CVE-2011-3923)
Server side template injection In org.apache.struts:struts2-core
8.1
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-XVPNF (CVE-2021-31805)
Remote command execution In org.apache.struts:struts2-core
8.1
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-SNAM2 (CVE-2020-17530)
Remote command execution In org.apache.struts:struts2-core
8.1
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-BTAWU (CVE-2019-0230)
Prototype Pollution In org.apache.struts:struts2-core
6.3
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-9PR3B (CVE-2018-11776)
Lack of data validation In org.apache.struts:struts2-core
7.2
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-7B458 (CVE-2017-5638)
Lack of data validation In org.apache.struts:struts2-core
9.1
Critical
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-D1YHR (CVE-2017-9805)
Insecure deserialization In org.apache.struts:struts2-rest-plugin
7.2
High
Ecosystem: Maven
Component: org.apache.struts:struts2-rest-plugin
FLAT-94JHJ (CVE-2017-9804)
Lack of data validation In org.apache.struts:struts2-core
6.6
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-L6V79 (CVE-2017-9793)
Lack of data validation In org.apache.struts:struts2-rest-plugin
6.6
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-rest-plugin
FLAT-ASPTQ (CVE-2017-9787)
Asymmetric denial of service In org.apache.struts:struts2-core
6.6
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-VV34T (CVE-2017-7672)
Lack of data validation In org.apache.struts:struts2-core
4.6
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-R5OYQ (CVE-2017-15707)
Lack of data validation In org.apache.struts:struts2-rest-plugin
6.6
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-rest-plugin
FLAT-A4N03 (CVE-2017-12611)
Lack of data validation In org.apache.struts:struts2-core
8.1
High
Ecosystem: Maven
Component: org.apache.struts:struts2-core
FLAT-IPTJH (CVE-2018-1327)
XPath injection In org.apache.struts:struts2-rest-plugin
4.9
Medium
Ecosystem: Maven
Component: org.apache.struts:struts2-rest-plugin