References https://github.com/zan8in/shiro https://github.com/myzxcg/ShiroKeyCheck https://github.com/projectdiscovery/nuclei-templates/issues/8243 https://shiro.apache.org/troubleshooting.html https://github.com/topics/shiro-keys https://k8gege.org/p/shiroexp.html https://teamssix.com/200619-233603.html https://www.tenable.com/plugins/nessus/159323 https://gitee.com/aaaddc/shiro_rce https://szczecin.github.io/2023/11/07/CVE-2016-4437-Apache-Shiro/
Related VulnerabilitiesPoCccm-detect: Clear-Com Core Configuration Manager Panel - DetectPoCCVE-2026-25527: changedetection.io <= 0.52.9 - Unauthenticated Path Traversalchangedetection.io /static/%2e%2e/flask_app.py 目录遍历漏洞(CVE-2026-25527)changedetection.io <= 0.53.9 存在路径遍历漏洞(CVE-2026-25527)PoCdbgate-anonymous-access: DbGate Anonymous Access - DetectionPoCCVE-2026-27645: Changedetection.io RSS Single Watch - Cross-Site Scriptingchangedetection.io存在反射xss漏洞(CVE-2026-27645)PoCCVE-2025-62780: ChangeDetection.io <= v0.50.33 - Stored XSS via Watch APIPoCopennms-dashboard-exposure: OpenNMS Dashboard - Exposure DetectionPoCCVE-2019-5591: FortiOS - Insecure LDAP Configuration DetectionPoCCVE-2024-28200: N-able N-central < 2024.2 - Authentication Bypass DetectionPoCsmtp-credentials-exposure: SMTP Credentials Exposure - DetectionPoCx-backend-server-header-detect: X-Backend-Server Header - Exposure