Struts

Vendor:

First CVE: Nov 22, 2005 · Active for 20 years

91
Total CVEs
More Total CVEs than 99% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
8.8%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Struts over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 22, 2005
20 years ago
Most Recent CVE
Jan 11, 2026
195 days ago

CVE Severity & Scoring

Struts91 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local1 (1.1%)
Network53 (58.2%)
Unknown37 (40.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (50.5%)
High8 (8.8%)
Unknown37 (40.7%)
User Interaction
None48 (52.7%)
Unknown37 (40.7%)
Required6 (6.6%)
Privileges Required
Low6 (6.6%)
High0 (0.0%)
None48 (52.7%)
Unknown37 (40.7%)

Top CVEs

Signals from CVEs in this product scope (91 CVEs).

91 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention
Aug 22, 20188.199YESYES
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type f
Sep 15, 20178.199YESYES
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Jul 10, 20179.899YESYES
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attem
Mar 11, 20179.899YESYES
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: p
Jul 20, 20139.899YESYES
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Dec 11, 20209.898YESYES
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of prop
Jan 8, 20129.897YESYES
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
Sep 14, 20209.894NOYES
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method:
Apr 26, 20168.192NOYES
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
Sep 20, 20179.890NOYES

Exploit Exposure

Signals from CVEs in this product scope (91 CVEs).

CISA KEV
8 CVEs
8.8% of CVEs· 97th percentile
Metasploit
18 CVEs
19.8% of CVEs· 97th percentile
Nuclei
16 CVEs
17.6% of CVEs· 98th percentile
ExploitDB
31 CVEs
34.1% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (91 CVEs).

Media Mentions

Signals from CVEs in this product scope (91 CVEs).

Top CNAs Publishing CVEs For Struts

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.5.948.128.4%01
2.5.857.624.6%01
2.5.748.128.4%01
2.5.648.128.4%01
2.5.567.321.0%01
2.5.457.623.4%01
2.5.357.623.4%01
2.5.267.321.0%01
2.5.1227.58.4%00
2.5.10.147.18.9%00
2.5.1057.624.6%01
2.5.167.321.0%01
2.587.822.0%01
2.3.968.121.4%01
2.3.8177.828.4%14
2.3.7177.828.4%14
2.3.638.734.0%01
2.3.538.734.0%01
2.3.4.1147.832.6%14
2.3.4167.629.2%14