Modsecurity
Vendor:
First CVE: Jun 3, 2009 · Active for 17 years
14
Total CVEs
More Total CVEs than 91% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Modsecurity over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2009
17 years ago
Most Recent CVE
May 21, 2025
430 days ago
CVE Severity & Scoring
Modsecurity14 CVEs
50%
50%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (42.9%)
Unknown8 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (42.9%)
High0 (0.0%)
Unknown8 (57.1%)
User Interaction
None6 (42.9%)
Unknown8 (57.1%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (42.9%)
Unknown8 (57.1%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4528MEDIUM The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart requ | Dec 28, 2012 | 5.0 | 33 | NO | YES |
CVE-2009-1902MEDIUM The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header na | Jun 3, 2009 | 5.0 | 30 | NO | YES |
CVE-2013-2765MEDIUM The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) | Jul 15, 2013 | 5.0 | 28 | NO | YES |
CVE-2021-42717HIGH ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to se | Dec 7, 2021 | 7.5 | 26 | NO | NO |
CVE-2025-47947HIGH ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of servic | May 21, 2025 | 7.5 | 25 | NO | NO |
CVE-2023-24021HIGH Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall w | Jan 20, 2023 | 7.5 | 25 | NO | NO |
CVE-2025-27110HIGH Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional | Feb 25, 2025 | 7.5 | 24 | NO | NO |
CVE-2022-48279HIGH In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-3 | Jan 20, 2023 | 7.5 | 24 | NO | NO |
CVE-2024-46292HIGH A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Sup | Oct 9, 2024 | 7.5 | 23 | NO | NO |
CVE-2013-1915HIGH ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an X | Apr 25, 2013 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
21.4% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Modsecurity
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.13 | 1 | 7.5 | 0.5% | 0 | 0 |
| 3.0.12 | 1 | 7.5 | 0.8% | 0 | 0 |