Beanshell is a lightweight, embeddable Java scripting engine that evaluates dynamic expressions and scripts within Java applications, presenting a narrow but potentially high-impact exposure vector when integrated into larger systems. The vendor's vulnerability surface centers on the core Beanshell interpreter and recurs around input-handling and expression-evaluation issues characteristic of dynamic scripting contexts. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Beanshell over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2510HIGH BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafte | Apr 7, 2016 | 8.1 | 66 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Beanshell.
Media articles that mention a CVE ID that affects a product developed by Beanshell — matched by CVE ID, not by vendor name.