CVE-2012-0391CISA KEVEPSS p99.4%

CVE-2012-0391Apache Struts 2 Improper Input Validation Vulnerability

Apache / Struts 2

Description

The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.

Scoring

EPSS75.07% probability of exploitation · percentile 99.4% · 2026-06-17T12:03:21Z

CISA KEV entry

Added to KEV: 2022-01-21

(incoming)1

TypeTargetConfidenceTier
KEVEntryApache Struts 2 Improper Input Validation Vulnerabilitykev-cve-2012-03910%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Apache Struts Improper Input Validation Vulnerability
CVE
Apache Struts 1 Improper Input Validation Vulnerability
CVE
Apache Struts Remote Code Execution Vulnerability
CVE
CVE-2025-68493
CVE
Apache Struts Deserialization of Untrusted Data Vulnerability
CVE
Apache Struts 1 ActionForm Denial-of-Service Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.