CVE-2018-16621: Sonatype Nexus Repository Manager

High severity, CVSS 7.2. EPSS: 5.2% chance of exploitation in the next 30 days.

Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.

Affected products

  • Sonatype Nexus Repository Manager: before 3.14.0 (fixed in 3.14.0)

Published 2018-11-15. Last modified 2026-06-17.