| Bug | Description |
|---|
| CVE-2026-33691 | The OWASP core rule set (CRS) is a set of generic attack detection rul ... |
| CVE-2026-21876 | The OWASP core rule set (CRS) is a set of generic attack detection rul ... |
| CVE-2023-38199 | coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does n ... |
| CVE-2022-39958 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a response bo ... |
| CVE-2022-39957 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a response bo ... |
| CVE-2022-39956 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rul ... |
| CVE-2022-39955 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rul ... |
| CVE-2021-35368 | OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1 ... |
| CVE-2020-22669 | Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a ... |
| CVE-2019-13464 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2 ... |
| CVE-2019-11388 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) throu ... |
| CVE-2019-11387 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) throu ... |
| CVE-2018-16384 | A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Co ... |