Codehaus Plexus is a Java utility library project that, despite a narrow product footprint centered on components like Plexus Utils and Plexus Archiver, occupies a significant position in the Maven ecosystem and sits embedded across a wide range of build tools and Java applications. The vulnerability disclosures associated with this vendor reflect the utility-library context, where individual flaws can propagate downstream to every dependent project. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codehaus Plexus over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67030HIGH Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attac | Mar 25, 2026 | 8.8 | 33 | NO | NO |
CVE-2017-1000487CRITICAL Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings. | Jan 3, 2018 | 9.8 | 33 | NO | NO |
CVE-2023-37460CRITICAL Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using | Jul 25, 2023 | 9.8 | 31 | NO | NO |
CVE-2018-1002200MEDIUM plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled d | Jul 25, 2018 | 5.5 | 26 | NO | NO |
CVE-2022-4244HIGH A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manip | Sep 25, 2023 | 7.5 | 19 | NO | NO |
CVE-2022-4245MEDIUM A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained | Sep 25, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codehaus Plexus.
Media articles that mention a CVE ID that affects a product developed by Codehaus Plexus — matched by CVE ID, not by vendor name.