Opensymphony

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    3
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2011-1772

    struts: Multiple XSS flaws in XWork

    Last Modified: Apr 11, 2025
    Published: Feb 22, 2011

    CVE-2011-2088

    struts: Allows remote attackers to obtain potentially sensitive information via vectors involving an s:submit element

    Last Modified: Apr 11, 2025
    Published: Feb 22, 2011

    CVE-2008-6504

    Struts2/WebWorks/XWork: ParameterInterceptors bypass allows OGNL statement execution

    Last Modified: Apr 23, 2026
    Published: Jun 12, 2008

    CVE-2007-4556

    Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.

    Last Modified: Apr 23, 2026
    Published: Aug 28, 2007
    Items Per Page
    Opensymphony Vulnerabilities & Security CVEs | CVE-DB