ModSecurity is a narrowly scoped open-source Web Application Firewall module and rule set deployed across web servers to detect and block HTTP-layer attacks. Its vulnerability footprint, while limited in volume, reflects the resource-intensive nature of real-time request inspection and log processing, with recurring weaknesses centered on uncontrolled resource consumption and improper handling of uploaded file types. Defenders should monitor this vendor's advisories for the Core Rule Set and mod_security module specifically, as updates may affect the integrity of application-layer attack detection; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Modsecurity over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1359MEDIUM Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contain | Mar 8, 2007 | 6.8 | 29 | NO | YES |
CVE-2019-13464HIGH An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically | Jul 9, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-11387MEDIUM An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf allows remote attackers to cause a denial of service | Apr 21, 2019 | 5.3 | 21 | NO | NO |
CVE-2004-1765HIGH Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST | Dec 31, 2004 | 7.5 | 21 | NO | NO |
CVE-2003-1171HIGH Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side scrip | Dec 31, 2003 | 7.5 | 21 | NO | NO |
CVE-2019-11391MEDIUM An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service | Apr 21, 2019 | 5.3 | 20 | NO | NO |
CVE-2019-11390MEDIUM An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service | Apr 21, 2019 | 5.3 | 20 | NO | NO |
CVE-2019-11389MEDIUM An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service | Apr 21, 2019 | 5.3 | 20 | NO | NO |
CVE-2019-11388MEDIUM An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf allows remote attackers to cause a denial of service | Apr 21, 2019 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Modsecurity.
Media articles that mention a CVE ID that affects a product developed by Modsecurity — matched by CVE ID, not by vendor name.