Shiro

Vendor:

First CVE: Nov 5, 2010 · Active for 15 years

24
Total CVEs
More Total CVEs than 95% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
4.2%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Shiro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 5, 2010
15 years ago
Most Recent CVE
Jun 17, 2026
37 days ago

CVE Severity & Scoring

Shiro24 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (4.2%)
Network21 (87.5%)
Unknown2 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (87.5%)
High1 (4.2%)
Unknown2 (8.3%)
User Interaction
None17 (70.8%)
Unknown2 (8.3%)
Required5 (20.8%)
Privileges Required
Low4 (16.7%)
High0 (0.0%)
None18 (75.0%)
Unknown2 (8.3%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access rest
Jun 7, 20169.899YESYES
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
Sep 17, 20219.873NONO
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Feb 3, 20219.871NONO
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass inte
Nov 5, 20105.059NOYES
Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.
Aug 17, 20207.551NONO
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expr
Jun 29, 20229.844NONO
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Jun 22, 20209.842NONO
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Mar 25, 20209.838NONO
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated
Jun 17, 20269.136NONO
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
Oct 12, 20229.831NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
1 CVE
4.2% of CVEs· 97th percentile
Metasploit
1 CVE
4.2% of CVEs· 96th percentile
Nuclei
1 CVE
4.2% of CVEs· 97th percentile
ExploitDB
2 CVEs
8.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Shiro

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0.056.60.4%00
2.0.037.21.5%00
1.3.117.59.7%00
1.2.217.55.5%00
1.2.117.55.5%00
1.2.017.55.5%00
1.1.017.55.5%00
1.0.017.55.5%00