CVE Tools

Org.apache.shiro:shiro-core

10 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Org.apache.shiro:shiro-core, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Org.apache.shiro:shiro-core CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Org.apache.shiro:shiro-core CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-021
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical660%
  • High220%
  • Medium110%
  • Low110%

Latest CVEs

The 10 most recently published vulnerabilities affecting Org.apache.shiro:shiro-core.

  1. CVE-2026-23901Apache Shiro: Brute force attack possible to determine valid user names2.5
  2. CVE-2023-46749Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting 6.5
  3. CVE-2022-40664Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher9.8
  4. CVE-2022-32532Authentication Bypass Vulnerability9.8
  5. CVE-2021-41303Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass9.8
  6. CVE-2020-13933Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.7.5
  7. CVE-2020-11989Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.9.8
  8. CVE-2020-1957Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.9.8
  9. CVE-2019-12422Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.7.5
  10. CVE-2016-4437Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an u...9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store