Apache Struts — CWE-117

All FrameworksApache StrutsCWE-117

1 CVEs categorized as CWE-117 in Apache Struts.

CVE-2025-54656MEDIUM2025
** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affects Apache Struts Extras: before 2. When using LookupDispatchAction, in some cases, Struts may print untrusted input to the logs without any filtering. Specially-crafted input may…