← Global Threat Landscape

CVE-2018-11776

Critical

93.6

RPS

Description

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

Source: NVD

Signals

CVSS
8.1
High · v3.1
EPSS
99.99%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Nov 2021
Fix commit
Fix commit known
Sources: MoreFixes, FreshFixes
Weakness
Not mapped
Published
22 Aug 2018
Last modified 27 Oct 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2018-11776

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2018-11776 · RPS 93.6 · DevSecure Intelligence