Spring Web MVC
100%
Total Score
99
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11157 spring-webmvc is vulnerable to Cross-site Scripting (XSS) in versions 7.0.0 - 7.0.7, 6.2.0 - 6.2.18, 6.1.0 - 6.1.27 and 5.3.0 - 5.3.48. | 5.3.0 - 5.3.486.1.0 - 6.1.276.2.0 - 6.2.18 +1 more | Medium |
AIKIDO-2026-11159 spring-webmvc is vulnerable to Open Redirect in versions 5.3.0 - 5.3.48, 6.1.0 - 6.1.27, 6.2.0 - 6.2.18 and 7.0.0 - 7.0.7. | 5.3.0 - 5.3.486.1.0 - 6.1.276.2.0 - 6.2.18 +1 more | Medium |
CVE-2026-22737 org.springframework:spring-webmvc is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 7.0.0-M1 - 7.0.6, 6.2.0 - 6.2.17, 6.0.0 - 6.1.21 and 5.3.0 - 5.3.39. | 5.3.0 - 5.3.396.0.0 - 6.1.216.2.0 - 6.2.17 +1 more | Medium |
CVE-2026-22735 org.springframework:spring-webmvc is vulnerable to Improper Locking in versions 7.0.0-M1 - 7.0.6, 6.2.0 - 6.2.17, 6.0.0 - 6.1.21 and 5.3.0 - 5.3.39. | 5.3.0 - 5.3.396.0.0 - 6.1.216.2.0 - 6.2.17 +1 more | Low |
AIKIDO-2025-10562 spring-webmvc is vulnerable to Path Traversal in versions 0.0.1 - 5.3.43, 6.0.0 - 6.1.13 and 6.2.0 - 6.2.09. | 0.0.1 - 5.3.436.0.0 - 6.1.136.2.0 - 6.2.09 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework:spring-aop Version 7.0.8 | — | — |
org.springframework:spring-beans Version 7.0.8 | — | — |
org.springframework:spring-context Version 7.0.8 | — | — |
org.springframework:spring-core Version 7.0.8 | — | — |
org.springframework:spring-expression Version 7.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant