Stanford's vulnerability profile centers on a small set of widely used natural-language processing and authentication research tools, including CoreNLP, the Stanford Parser, and WebAuth, that are embedded across academic institutions and deployed in production systems beyond their original research scope. Vulnerabilities affecting these products skew strongly toward critical-severity outcomes and recur through structural weaknesses in XML entity handling, code injection pathways, and credential protection that reflect the parser-oriented and web-facing nature of the toolset. Defenders should prioritize patching instances of these tools, particularly in exposed or internet-connected deployments, and treat them as high-value targets despite their research-software provenance; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stanford over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54499HIGH Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.mode | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2022-0239CRITICAL corenlp is vulnerable to Improper Restriction of XML External Entity Reference | Jan 17, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-3878CRITICAL corenlp is vulnerable to Improper Restriction of XML External Entity Reference | Oct 15, 2021 | 9.8 | 32 | NO | NO |
CVE-2021-44550CRITICAL An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159). | Feb 24, 2022 | 9.8 | 28 | NO | NO |
CVE-2023-39020CRITICAL stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is explo | Jul 28, 2023 | 9.8 | 26 | NO | NO |
CVE-2021-3869HIGH corenlp is vulnerable to Improper Restriction of XML External Entity Reference | Oct 19, 2021 | 7.5 | 25 | NO | NO |
CVE-2013-2106HIGH webauth before 4.6.1 has authentication credential disclosure | Dec 3, 2019 | 7.5 | 19 | NO | NO |
CVE-2022-0198HIGH corenlp is vulnerable to Improper Restriction of XML External Entity Reference | Jan 13, 2022 | 7.1 | 18 | NO | NO |
CVE-2009-2945MEDIUM weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of | Sep 15, 2009 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stanford.
Media articles that mention a CVE ID that affects a product developed by Stanford — matched by CVE ID, not by vendor name.