24 exploited vulnerabilities in Modsecurity
- Vendors
- Debian, Unknown, Apache, Linux Mint, Suse, Canonical
- With known exploits
- 24
- Affected Trustwave Modsecurity versions
- < 2.9.7, 2.9.9, 2.9.6, 2.9.5, 3.0.12, 2.7.6, 2.7.4, 2.5.9
- Affected Owasp Owasp Modsecurity Core Rule Set versions
- < 3.3.8, 4.22.0
- Affected Owasp Modsecurity versions
- < 3.0.16, 3.0.12, 3.0.15, 2.9.10, 3.0.8, 3.0.6, 3.0.4, 3.0.10, 3.0.9, 3.0.0
- Affected Mod Security versions
- = 1.7, 1.7.1, 1.7.2, 1.7.4, 1.7.5, 1.9.4, 2.1
Vulnerabilities with exploits
Highest CVSS first — 8 of these already have exploit code on Sploitus
CVE-2020-22669
CVE-2023-24021
CVE-2026-21876 3 exploits
CVE-2026-52747
CVE-2024-1019
CVE-2026-42268
CVE-2025-52891
CVE-2025-48866
CVE-2025-47947
CVE-2022-48279
CVE-2021-42717 1 exploit
CVE-2020-15598 1 exploit
CVE-2024-46292
CVE-2023-38285
CVE-2023-28882
CVE-2003-1171
CVE-2025-54571
CVE-2007-1359 1 exploit
CVE-2018-13065 3 exploits
CVE-2026-52761
CVE-2019-25043
CVE-2013-5705 1 exploit
CVE-2013-2765 4 exploits
CVE-2009-1902 1 exploit