The Open Web Application Security Project (OWASP) maintains a portfolio of security tooling and libraries focused on web application protection and secure coding practices, including widely embedded components such as ModSecurity and its Core Rule Set. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including cross-site scripting, improper output encoding and escaping, resource management flaws, and authorization weaknesses that reflect the complexity of parsing, filtering, and access control in web security middleware. The exposure concentrates in ModSecurity and related rule-set and encoding libraries that sit in the request path or handle user-supplied data, making patching relevant across a large installed base of web application firewalls and integrated security stacks. Defenders should prioritize this vendor's advisories where ModSecurity or related OWASP libraries are in active use, particularly for internet-facing deployments; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Owasp over time
Signals from CVEs in this vendor scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-21876MEDIUM The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922 | Jan 8, 2026 | 5.3 | 43 | NO | YES |
CVE-2026-52747HIGH ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmo | Jul 10, 2026 | 8.6 | 41 | NO | NO |
CVE-2007-4385MEDIUM OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests instead of form-urlencoded requests. NOTE: this might be u | Aug 17, 2007 | 6.8 | 32 | NO | YES |
CVE-2022-39956CRITICAL The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the | Sep 20, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-23457CRITICAL ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getVa | Apr 25, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-35368CRITICAL OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname. | Nov 5, 2021 | 9.8 | 31 | NO | NO |
CVE-2026-30923HIGH ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project. A segm | May 5, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-40316HIGH OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in | Apr 15, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-33691HIGH The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identif | Apr 2, 2026 | 7.5 | 30 | NO | NO |
CVE-2023-38199CRITICAL coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might allow attackers to bypass a WAF | Jul 13, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (49 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Owasp.
Media articles that mention a CVE ID that affects a product developed by Owasp — matched by CVE ID, not by vendor name.