CVE Tools

Org.apache.struts:struts2-core

60 CVEs tracked. 5 of them are in CISA KEV.

This hub aggregates every CVE we track for Org.apache.struts:struts2-core, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Org.apache.struts:struts2-core CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Org.apache.struts:struts2-core CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-122
2026-011
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 60 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2033%
  • High1728%
  • Medium2237%
  • Low12%

Latest CVEs

The 15 most recently published vulnerabilities affecting Org.apache.struts:struts2-core.

  1. CVE-2025-68493Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component8.1
  2. CVE-2025-66675Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - version ranges fixed8.2
  3. CVE-2025-64775Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS)7.5
  4. CVE-2024-53677Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks9.8
  5. CVE-2023-50164Apache Struts: File upload component had a directory traversal vulnerability9.8
  6. CVE-2023-41835Apache Struts: excessive disk usage7.5
  7. CVE-2023-34396Apache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart forms4.3
  8. CVE-2023-34149Apache Struts: DoS via OOM owing to not properly checking of list bounds4.3
  9. CVE-2021-31805Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.9.8
  10. CVE-2020-17530Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.9.8
  11. CVE-2019-0233An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.7.5
  12. CVE-2019-0230Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.9.8
  13. CVE-2015-2992Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.6.1
  14. CVE-2012-1592A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.8.8
  15. CVE-2011-3923Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store