Mod Security is a widely embedded open-source web application firewall module for Apache HTTP Server that provides request filtering and attack detection across a substantial range of deployments despite a narrow product footprint. The limited vulnerability record reflects the module's focused security-oriented function, with disclosed issues classified under generic or insufficient-information categories. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mod Security over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1359MEDIUM Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contain | Mar 8, 2007 | 6.8 | 29 | NO | YES |
CVE-2019-13464HIGH An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically | Jul 9, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-11387MEDIUM An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf allows remote attackers to cause a denial of service | Apr 21, 2019 | 5.3 | 21 | NO | NO |
CVE-2004-1765HIGH Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST | Dec 31, 2004 | 7.5 | 21 | NO | NO |
CVE-2003-1171HIGH Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side scrip | Dec 31, 2003 | 7.5 | 21 | NO | NO |
CVE-2019-11391MEDIUM An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service | Apr 21, 2019 | 5.3 | 20 | NO | NO |
CVE-2019-11390MEDIUM An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service | Apr 21, 2019 | 5.3 | 20 | NO | NO |
CVE-2019-11389MEDIUM An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service | Apr 21, 2019 | 5.3 | 20 | NO | NO |
CVE-2019-11388MEDIUM An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf allows remote attackers to cause a denial of service | Apr 21, 2019 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mod Security.
Media articles that mention a CVE ID that affects a product developed by Mod Security — matched by CVE ID, not by vendor name.