Storm
This hub aggregates every CVE we track for Storm, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
23
CVEs tracked
8
Critical
6
High
0
In CISA KEV
Severity distribution
CRITICAL8MEDIUM7HIGH6LOW2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
3
0
0
0
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Storm.
- CVE-2026-41081Apache Storm Client: Anonymous principal assigned on TLS client certificate verification failure6.5
- CVE-2026-35337Apache Storm Client: RCE through Unsafe Deserialization via Kerberos TGT Credential Handling8.8
- CVE-2026-35565Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Storm UI5.4
- CVE-2023-43123Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files5.5
- CVE-2021-40865Unsafe Pre-Authentication Deserialization In Workers9.8
- CVE-2021-38294Shell Command Injection Vulnerability in Nimbus Thrift Server9.8
- CVE-2018-11779In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a ...9.8
- CVE-2019-0202The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files...7.5
- CVE-2018-1331In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary cod...8.8
- CVE-2018-8008Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (af...5.5
- CVE-2018-1332Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Stor...6.5
- CVE-2014-0115Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log.7.5
- CVE-2017-9799It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor ...8.8
- CVE-2015-3188The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.9.8
- CVE-2010-2158Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary ...2.1
Product normalization is registry-driven with AI assist and human review. How it works