codehaus-plexus records
6 published records for vendor codehaus-plexus.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-91 XML Injection (aka Blind XPath Injection)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2017-1000487Proof of concept | Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.codehaus-plexus · plexus-utils · CWE-78 | Critical9.8 | — | 6.5% | Jan 3, 2018 |
40Plan | CVE-2023-37460Proof of concept | Plexus Archiver vulnerable to Arbitrary File Creation in AbstractUnArchivercodehaus-plexus · plexus-archiver · CWE-22 | Critical9.8 | — | 2.5% | Jul 25, 2023 |
35Monitor | CVE-2025-67030No exploit | Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2dcodehaus-plexus · plexus-utils · CWE-22 | High8.8 | — | 0.7% | Mar 25, 2026 |
30Monitor | CVE-2022-4244Proof of concept | Codehaus-plexus: directory traversalcodehaus-plexus · plexus-utils · CWE-22 | High7.5 | — | 1.3% | Sep 25, 2023 |
25Monitor | CVE-2018-1002200Proof of concept | plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) codehaus-plexus · plexus-archiver · CWE-22 | Medium5.5 | — | 11.6% | Jul 25, 2018 |
17Monitor | CVE-2022-4245No exploit | Codehaus-plexus: xml external entity (xxe) injectioncodehaus-plexus · plexus-utils · CWE-91 | Medium4.3 | — | 0.7% | Sep 25, 2023 |
- CVE-2017-100048741Plan
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
CriticalCVSS 9.8Proof of conceptEPSS 6%codehaus-plexus · plexus-utilsJan 3, 2018
- CVE-2023-3746040Plan
Plexus Archiver vulnerable to Arbitrary File Creation in AbstractUnArchiver
CriticalCVSS 9.8Proof of conceptEPSS 2%codehaus-plexus · plexus-archiverJul 25, 2023
- CVE-2025-6703035Monitor
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d
HighCVSS 8.8No exploitEPSS 1%codehaus-plexus · plexus-utilsMar 25, 2026
- CVE-2022-424430Monitor
Codehaus-plexus: directory traversal
HighCVSS 7.5Proof of conceptEPSS 1%codehaus-plexus · plexus-utilsSep 25, 2023
- CVE-2018-100220025Monitor
plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash)
MediumCVSS 5.5Proof of conceptEPSS 12%codehaus-plexus · plexus-archiverJul 25, 2018
- CVE-2022-424517Monitor
Codehaus-plexus: xml external entity (xxe) injection
MediumCVSS 4.3No exploitEPSS 1%codehaus-plexus · plexus-utilsSep 25, 2023