Struts
Vendor:
First CVE: Nov 22, 2005 · Active for 20 years
91
Total CVEs
More Total CVEs than 99% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
8.8%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Struts over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 22, 2005
20 years ago
Most Recent CVE
Jan 11, 2026
195 days ago
CVE Severity & Scoring
Struts91 CVEs
40%
42%
18%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.1%)
Network53 (58.2%)
Unknown37 (40.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (50.5%)
High8 (8.8%)
Unknown37 (40.7%)
User Interaction
None48 (52.7%)
Unknown37 (40.7%)
Required6 (6.6%)
Privileges Required
Low6 (6.6%)
High0 (0.0%)
None48 (52.7%)
Unknown37 (40.7%)
Top CVEs
Signals from CVEs in this product scope (91 CVEs).
91 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11776HIGH Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention | Aug 22, 2018 | 8.1 | 99 | YES | YES |
CVE-2017-9805HIGH The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type f | Sep 15, 2017 | 8.1 | 99 | YES | YES |
CVE-2017-9791CRITICAL The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage. | Jul 10, 2017 | 9.8 | 99 | YES | YES |
CVE-2017-5638CRITICAL The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attem | Mar 11, 2017 | 9.8 | 99 | YES | YES |
CVE-2013-2251CRITICAL Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: p | Jul 20, 2013 | 9.8 | 99 | YES | YES |
CVE-2020-17530CRITICAL Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25. | Dec 11, 2020 | 9.8 | 98 | YES | YES |
CVE-2012-0391CRITICAL The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of prop | Jan 8, 2012 | 9.8 | 97 | YES | YES |
CVE-2019-0230CRITICAL Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. | Sep 14, 2020 | 9.8 | 94 | NO | YES |
CVE-2016-3081HIGH Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: | Apr 26, 2016 | 8.1 | 92 | NO | YES |
CVE-2017-12611CRITICAL In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack. | Sep 20, 2017 | 9.8 | 90 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (91 CVEs).
CISA KEV
8 CVEs
8.8% of CVEs· 97th percentile
Metasploit
18 CVEs
19.8% of CVEs· 97th percentile
Nuclei
16 CVEs
17.6% of CVEs· 98th percentile
ExploitDB
31 CVEs
34.1% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (91 CVEs).
Media Mentions
Signals from CVEs in this product scope (91 CVEs).
Top CNAs Publishing CVEs For Struts
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.5.9 | 4 | 8.1 | 28.4% | 0 | 1 |
| 2.5.8 | 5 | 7.6 | 24.6% | 0 | 1 |
| 2.5.7 | 4 | 8.1 | 28.4% | 0 | 1 |
| 2.5.6 | 4 | 8.1 | 28.4% | 0 | 1 |
| 2.5.5 | 6 | 7.3 | 21.0% | 0 | 1 |
| 2.5.4 | 5 | 7.6 | 23.4% | 0 | 1 |
| 2.5.3 | 5 | 7.6 | 23.4% | 0 | 1 |
| 2.5.2 | 6 | 7.3 | 21.0% | 0 | 1 |
| 2.5.12 | 2 | 7.5 | 8.4% | 0 | 0 |
| 2.5.10.1 | 4 | 7.1 | 8.9% | 0 | 0 |
| 2.5.10 | 5 | 7.6 | 24.6% | 0 | 1 |
| 2.5.1 | 6 | 7.3 | 21.0% | 0 | 1 |
| 2.5 | 8 | 7.8 | 22.0% | 0 | 1 |
| 2.3.9 | 6 | 8.1 | 21.4% | 0 | 1 |
| 2.3.8 | 17 | 7.8 | 28.4% | 1 | 4 |
| 2.3.7 | 17 | 7.8 | 28.4% | 1 | 4 |
| 2.3.6 | 3 | 8.7 | 34.0% | 0 | 1 |
| 2.3.5 | 3 | 8.7 | 34.0% | 0 | 1 |
| 2.3.4.1 | 14 | 7.8 | 32.6% | 1 | 4 |
| 2.3.4 | 16 | 7.6 | 29.2% | 1 | 4 |