Known Vulnerabilities for Owasp Modsecurity Core Rule Set by Owasp
Listed below are 9 of the newest known vulnerabilities associated with "Owasp Modsecurity Core Rule Set" by "Owasp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-33691 json | Not Provided | 2026-04-02 | 2026-04-18 | |
| CVE-2026-21876 json | Not Provided | 2026-01-08 | 2026-04-09 | |
| CVE-2022-39958 json | The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetect... | 7.5 - HIGH | 2022-09-20 | 2023-11-07 |
| CVE-2022-39957 json | The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header fie... | 7.5 - HIGH | 2022-09-20 | 2023-11-07 |
| CVE-2022-39956 json | The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting ... | 9.8 - CRITICAL | 2022-09-20 | 2023-11-07 |
| CVE-2022-39955 json | The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Con... | 9.8 - CRITICAL | 2022-09-20 | 2023-11-07 |
| CVE-2021-35368 json | OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body ... | 9.8 - CRITICAL | 2021-11-05 | 2023-11-07 |
| CVE-2020-22669 json | Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use t... | 9.8 - CRITICAL | 2022-09-02 | 2023-02-16 |
| CVE-2018-16384 json | A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 ... | 7.5 - HIGH | 2018-09-03 | 2023-01-30 |