Modsecurity

Vendor:

First CVE: Jun 3, 2009 · Active for 17 years

14
Total CVEs
More Total CVEs than 91% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Modsecurity over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2009
17 years ago
Most Recent CVE
May 21, 2025
430 days ago

CVE Severity & Scoring

Modsecurity14 CVEs
All CVEs352,427 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (42.9%)
Unknown8 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (42.9%)
High0 (0.0%)
Unknown8 (57.1%)
User Interaction
None6 (42.9%)
Unknown8 (57.1%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (42.9%)
Unknown8 (57.1%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart requ
Dec 28, 20125.033NOYES
The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header na
Jun 3, 20095.030NOYES
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption)
Jul 15, 20135.028NOYES
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to se
Dec 7, 20217.526NONO
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of servic
May 21, 20257.525NONO
Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall w
Jan 20, 20237.525NONO
Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional
Feb 25, 20257.524NONO
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-3
Jan 20, 20237.524NONO
A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Sup
Oct 9, 20247.523NONO
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an X
Apr 25, 20137.520NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
21.4% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Modsecurity

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0.1317.50.5%00
3.0.1217.50.8%00