OWASP records
49 published records for vendor owasp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 81.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-404 Improper Resource Shutdown or Release3
- CWE-863 Incorrect Authorization3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-310 Cryptographic Issues2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
49 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-42575No exploit | The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.owasp · java html sanitizer | Critical9.8 | — | 3.0% | Oct 18, 2021 |
40Plan | CVE-2022-23457Proof of concept | Path Traversal in ESAPIowasp · enterprise security api · CWE-22 | Critical9.8 | — | 2.8% | Apr 25, 2022 |
40Plan | CVE-2021-35368No exploit | OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trowasp · owasp modsecurity core rule set | Critical9.8 | — | 2.7% | Nov 5, 2021 |
40Plan | CVE-2021-23899No exploit | OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input.owasp · json-sanitizer · CWE-611 | Critical9.8 | — | 2.1% | Jan 13, 2021 |
39Monitor | CVE-2022-39955No exploit | Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type headerowasp · owasp modsecurity core rule set · CWE-863 | Critical9.8 | — | 1.4% | Sep 20, 2022 |
39Monitor | CVE-2020-22669No exploit | Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability.owasp · owasp modsecurity core rule set · CWE-89 | Critical9.8 | — | 1.3% | Sep 2, 2022 |
39Monitor | CVE-2022-39956No exploit | Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encodiowasp · owasp modsecurity core rule set · CWE-863 | Critical9.8 | — | 1.2% | Sep 20, 2022 |
39Monitor | CVE-2023-38199No exploit | coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms.owasp · coreruleset · CWE-843 | Critical9.8 | — | 0.7% | Jul 12, 2023 |
39Monitor | CVE-2025-66022No exploit | FACTION Unauthenticated Custom Extension Upload leads to RCEowasp · faction · CWE-287 | Critical9.8 | — | 0.7% | Nov 25, 2025 |
35Monitor | CVE-2023-48171No exploit | An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.owasp · defectdojo · CWE-269 | High8.8 | — | 0.6% | Aug 12, 2024 |
35Monitor | CVE-2026-40316No exploit | OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflowowasp · owasp blt · CWE-94 | High8.8 | — | 0.6% | Apr 15, 2026 |
35Monitor | CVE-2021-28490No exploit | In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.owasp · csrfguard · CWE-352 | High8.8 | — | 0.5% | Aug 19, 2021 |
34Monitor | CVE-2024-1019No exploit | WAF bypass of the ModSecurity v3 release lineowasp · modsecurity · CWE-20 | High8.6 | — | 0.7% | Jan 30, 2024 |
34Monitor | CVE-2026-52747No exploit | ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypassowasp · modsecurity · CWE-180 | High8.6 | — | 0.5% | Jul 10, 2026 |
34Monitor | CVE-2025-66021No exploit | OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitizationowasp · java html sanitizer · CWE-79 | High8.6 | — | 0.2% | Nov 25, 2025 |
32Monitor | CVE-2018-12036Proof of concept | OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenaowasp · dependency-check · CWE-22 | High7.8 | — | 1.7% | Jun 7, 2018 |
32Monitor | CVE-2026-30923No exploit | libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query stringsowasp · modsecurity · CWE-125 | High8.2 | — | 0.5% | May 5, 2026 |
32Monitor | CVE-2026-42268No exploit | ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operatorsowasp · modsecurity · CWE-191 | High8.2 | — | 0.5% | May 12, 2026 |
31Monitor | CVE-2021-42717Proof of concept | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.owasp · modsecurity · CWE-674 | High7.5 | — | 3.2% | Dec 7, 2021 |
31Monitor | CVE-2020-15598No exploit | Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request.owasp · modsecurity · CWE-835 | High7.5 | — | 2.9% | Oct 6, 2020 |
31Monitor | CVE-2019-19886No exploit | Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to owasp · modsecurity · CWE-404 | High7.5 | — | 2.5% | Jan 21, 2020 |
31Monitor | CVE-2021-23900No exploit | OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input.owasp · json-sanitizer | High7.5 | — | 2.1% | Jan 13, 2021 |
31Monitor | CVE-2018-16384No exploit | A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} wherowasp · owasp modsecurity core rule set · CWE-89 | High7.5 | — | 1.7% | Sep 2, 2018 |
30Monitor | CVE-2026-33691Proof of concept | OWASP CRS: Whitespace padding in filenames bypasses file upload extension checksowasp · owasp modsecurity core rule set · CWE-178 | High7.5 | — | 1.6% | Apr 2, 2026 |
30Monitor | CVE-2022-39958No exploit | Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte rangeowasp · owasp modsecurity core rule set · CWE-863 | High7.5 | — | 1.2% | Sep 20, 2022 |
- CVE-2021-4257540Plan
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
CriticalCVSS 9.8No exploitEPSS 3%owasp · java html sanitizerOct 18, 2021
- CVE-2022-2345740Plan
Path Traversal in ESAPI
CriticalCVSS 9.8Proof of conceptEPSS 3%owasp · enterprise security apiApr 25, 2022
- CVE-2021-3536840Plan
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a tr
CriticalCVSS 9.8No exploitEPSS 3%owasp · owasp modsecurity core rule setNov 5, 2021
- CVE-2021-2389940Plan
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input.
CriticalCVSS 9.8No exploitEPSS 2%owasp · json-sanitizerJan 13, 2021
- CVE-2022-3995539Monitor
Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header
CriticalCVSS 9.8No exploitEPSS 1%owasp · owasp modsecurity core rule setSep 20, 2022
- CVE-2020-2266939Monitor
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%owasp · owasp modsecurity core rule setSep 2, 2022
- CVE-2022-3995639Monitor
Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encodi
CriticalCVSS 9.8No exploitEPSS 1%owasp · owasp modsecurity core rule setSep 20, 2022
- CVE-2023-3819939Monitor
coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms.
CriticalCVSS 9.8No exploitEPSS 1%owasp · corerulesetJul 12, 2023
- CVE-2025-6602239Monitor
FACTION Unauthenticated Custom Extension Upload leads to RCE
CriticalCVSS 9.8No exploitEPSS 1%owasp · factionNov 25, 2025
- CVE-2023-4817135Monitor
An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.
HighCVSS 8.8No exploitEPSS 1%owasp · defectdojoAug 12, 2024
- CVE-2026-4031635Monitor
OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow
HighCVSS 8.8No exploitEPSS 1%owasp · owasp bltApr 15, 2026
- CVE-2021-2849035Monitor
In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.
HighCVSS 8.8No exploitEPSS 1%owasp · csrfguardAug 19, 2021
- CVE-2024-101934Monitor
WAF bypass of the ModSecurity v3 release line
HighCVSS 8.6No exploitEPSS 1%owasp · modsecurityJan 30, 2024
- CVE-2026-5274734Monitor
ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass
HighCVSS 8.6No exploitEPSS 0%owasp · modsecurityJul 10, 2026
- CVE-2025-6602134Monitor
OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
HighCVSS 8.6No exploitEPSS 0%owasp · java html sanitizerNov 25, 2025
- CVE-2018-1203632Monitor
OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filena
HighCVSS 7.8Proof of conceptEPSS 2%owasp · dependency-checkJun 7, 2018
- CVE-2026-3092332Monitor
libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query strings
HighCVSS 8.2No exploitEPSS 1%owasp · modsecurityMay 5, 2026
- CVE-2026-4226832Monitor
ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators
HighCVSS 8.2No exploitEPSS 0%owasp · modsecurityMay 12, 2026
- CVE-2021-4271731Monitor
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.
HighCVSS 7.5Proof of conceptEPSS 3%owasp · modsecurityDec 7, 2021
- CVE-2020-1559831Monitor
Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request.
HighCVSS 7.5No exploitEPSS 3%owasp · modsecurityOct 6, 2020
- CVE-2019-1988631Monitor
Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to
HighCVSS 7.5No exploitEPSS 3%owasp · modsecurityJan 21, 2020
- CVE-2021-2390031Monitor
OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input.
HighCVSS 7.5No exploitEPSS 2%owasp · json-sanitizerJan 13, 2021
- CVE-2018-1638431Monitor
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} wher
HighCVSS 7.5No exploitEPSS 2%owasp · owasp modsecurity core rule setSep 2, 2018
- CVE-2026-3369130Monitor
OWASP CRS: Whitespace padding in filenames bypasses file upload extension checks
HighCVSS 7.5Proof of conceptEPSS 2%owasp · owasp modsecurity core rule setApr 2, 2026
- CVE-2022-3995830Monitor
Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte range
HighCVSS 7.5No exploitEPSS 1%owasp · owasp modsecurity core rule setSep 20, 2022