Opensymphony
2 CVEs tracked since 2011. Since May 2011, none of them reached CISA KEV.
Opensymphony CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2011-05 | 2 | 0 |
Products
The products that kept showing up in Opensymphony's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 4 most recently published vulnerabilities affecting Opensymphony.
- CVE-2011-2088XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors i...5.0
- CVE-2011-1772Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script...2.6
- CVE-2008-6504ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context o...5.0
- CVE-2007-4556Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expressi...6.8
The record
- Peak rank
- #39 in May 2011
- Busiest month shown
- May 2011, 2 CVEs
- Months with a KEV entry
- 0 since May 2011
- Monthly snapshots
- 1 since 2011