Shiro
Vendor:
First CVE: Nov 5, 2010 · Active for 15 years
24
Total CVEs
More Total CVEs than 95% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
4.2%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Shiro over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 5, 2010
15 years ago
Most Recent CVE
Jun 17, 2026
37 days ago
CVE Severity & Scoring
Shiro24 CVEs
33%
21%
42%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (4.2%)
Network21 (87.5%)
Unknown2 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (87.5%)
High1 (4.2%)
Unknown2 (8.3%)
User Interaction
None17 (70.8%)
Unknown2 (8.3%)
Required5 (20.8%)
Privileges Required
Low4 (16.7%)
High0 (0.0%)
None18 (75.0%)
Unknown2 (8.3%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4437CRITICAL Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access rest | Jun 7, 2016 | 9.8 | 99 | YES | YES |
CVE-2021-41303CRITICAL Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0. | Sep 17, 2021 | 9.8 | 73 | NO | NO |
CVE-2020-17523CRITICAL Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. | Feb 3, 2021 | 9.8 | 71 | NO | NO |
CVE-2010-3863MEDIUM Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass inte | Nov 5, 2010 | 5.0 | 59 | NO | YES |
CVE-2020-13933HIGH Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass. | Aug 17, 2020 | 7.5 | 51 | NO | NO |
CVE-2022-32532CRITICAL Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expr | Jun 29, 2022 | 9.8 | 44 | NO | NO |
CVE-2020-11989CRITICAL Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass. | Jun 22, 2020 | 9.8 | 42 | NO | NO |
CVE-2020-1957CRITICAL Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass. | Mar 25, 2020 | 9.8 | 38 | NO | NO |
CVE-2026-49268CRITICAL A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated | Jun 17, 2026 | 9.1 | 36 | NO | NO |
CVE-2022-40664CRITICAL Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher. | Oct 12, 2022 | 9.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
1 CVE
4.2% of CVEs· 97th percentile
Metasploit
1 CVE
4.2% of CVEs· 96th percentile
Nuclei
1 CVE
4.2% of CVEs· 97th percentile
ExploitDB
2 CVEs
8.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Shiro
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.0 | 5 | 6.6 | 0.4% | 0 | 0 |
| 2.0.0 | 3 | 7.2 | 1.5% | 0 | 0 |
| 1.3.1 | 1 | 7.5 | 9.7% | 0 | 0 |
| 1.2.2 | 1 | 7.5 | 5.5% | 0 | 0 |
| 1.2.1 | 1 | 7.5 | 5.5% | 0 | 0 |
| 1.2.0 | 1 | 7.5 | 5.5% | 0 | 0 |
| 1.1.0 | 1 | 7.5 | 5.5% | 0 | 0 |
| 1.0.0 | 1 | 7.5 | 5.5% | 0 | 0 |