Apache Struts XWork - XML External Entity Injection
CVE-2025-68493
Verified
Description
Apache Struts 2.0.0 < 2.2.1 and 2.2.1 <= versions <= 6.1.0 contain an XML external entity injection caused by missing XML validation, letting attackers potentially disclose files or cause denial of service, exploit requires crafted XML input
Severity
High
CVSS Score
8.1
Exploit Probability
46%
Affected Product
struts
Published Date
July 29, 2026
Template Author
pussycat0x
CVE-2025-68493.yaml
8.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
CVE ID:
cve-2025-68493
CWE ID:
cwe-611
Remediation Steps
Upgrade to version 6.1.1.