Skip to content

Known CVE

Apache Struts XWork - XML External Entity Injection

Apache Struts 2.0.0 < 2.2.1 and 2.2.1 <= versions <= 6.1.0 contain an XML external entity injection caused by missing XML validation, letting attackers potentially disclose files or cause denial of service, exploit requires crafted XML input

CVE-2025-68493

High2025CVSS 8.1CWE-611

cve2025 · apache · struts · struts2 · xxe · oast · oob · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website