Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Springsource

First CVE: Apr 27, 2009Active for: 17 yearsTotal CVEs: 10
30.9
VTI Score
Low

Springsource maintains a modestly represented portfolio of Java application frameworks, servers, and management tools that sit in the middleware and application-runtime layer of enterprise deployments. The vendor's vulnerability profile concentrates in the Spring Framework and its associated server and management products, with recurring weaknesses centered on web-tier input handling and code generation, including cross-site scripting, cross-site request forgery, and code injection. Vulnerabilities affecting this vendor frequently acquire public exploit code, underscoring the accessibility and appeal of these widely integrated components; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Springsource over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2009
17 years ago
Most Recent CVE
Apr 17, 2014
4,481 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-0054MEDIUM
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote atta
Apr 17, 20146.873NONO
CVE-2010-1622MEDIUM
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request contai
Jun 21, 20106.061NOYES
CVE-2011-2730HIGH
VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twi
Dec 5, 20127.530NONO
CVE-2013-4152MEDIUM
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers t
Jan 23, 20146.829NONO
CVE-2009-2907MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Management Suite (AMS) before 2.0.0.SR4, Hyperic HQ Open Source befo
Mar 24, 20104.325NOYES
CVE-2013-7315MEDIUM
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-depende
Jan 23, 20146.823NONO
CVE-2009-2898LOW
Cross-site scripting (XSS) vulnerability in the Alerts list feature in the web interface in SpringSource Hyperic HQ 3.2.x before 3.2.6.1, 4.0.x before 4.0.3.1, 4.1.x before 4.1.2.1
Oct 13, 20093.522NOYES
CVE-2012-1833MEDIUM
VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions an
Sep 28, 20125.019NONO
CVE-2009-2897MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in hq/web/common/GenericError.jsp in the generic exception handler in the web interface in SpringSource Hyperic HQ 3.2.x before
Oct 13, 20094.316NONO
CVE-2009-1190MEDIUM
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Fr
Apr 27, 20095.016NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
10%
80%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown10 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown10 (100.0%)
User Interaction
None0 (0.0%)
Unknown10 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown10 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
30.0% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Springsource.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Springsource — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Springsource's Products

View all 2 CNAs →

Top CWEs