Known CVE
Apache Struts XWork - XML External Entity Injection
Apache Struts 2.0.0 < 2.2.1 and 2.2.1 <= versions <= 6.1.0 contain an XML external entity injection caused by missing XML validation, letting attackers potentially disclose files or cause denial of service, exploit requires crafted XML input
CVE-2025-68493
High2025CVSS 8.1CWE-611
cve2025 · apache · struts · struts2 · xxe · oast · oob · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website