Org.apache.shiro:shiro-core
10 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Org.apache.shiro:shiro-core, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Org.apache.shiro:shiro-core CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical6
- High2
- Medium1
- Low1
Latest CVEs
The 10 most recently published vulnerabilities affecting Org.apache.shiro:shiro-core.
- CVE-2026-23901Apache Shiro: Brute force attack possible to determine valid user names2.5
- CVE-2023-46749Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting 6.5
- CVE-2022-40664Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher9.8
- CVE-2022-32532Authentication Bypass Vulnerability9.8
- CVE-2021-41303Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass9.8
- CVE-2020-13933Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.7.5
- CVE-2020-11989Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.9.8
- CVE-2020-1957Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.9.8
- CVE-2019-12422Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.7.5
- CVE-2016-4437Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an u...9.8
Product grouping is registry-driven, with AI assist and human review. How it works