Search/CVE-2014-1904
CVE

CVE-2014-1904

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.

CVSS v3.1
EPSS
6.90%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 7, 2026
3.55pp
3.35% → 6.90% over 2 tracked changes
Connections
2 relationships
Timeline
disclosure → media coverage
Mar 20, 2014
Disclosure — published as a CVE record. · last revised by NVD May 6, 2026