Payara

First CVE: Nov 15, 2023Active for: 3 years
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
2.0
Avg CVEs / Year
More Avg CVEs / Year than 11% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Payara as a CNA, 50.0% affect products that Payara develops as a vendor.

50.0%
50.0%
Self-reported: 4Third-party: 4

Of all the CVEs published that affect products developed by Payara, 50.0% are self-published by Payara as a CNA.

50.0%
50.0%
Self-published: 4Published by other CNAs: 4

Trends Over Time

The number and severity of CVEs published by Payara over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 15, 2023
2 years ago
Most Recent CVE
Jun 24, 2026
30 days ago

Top CVEs

All CVEs published by Payara as a CNA, regardless of affected vendor or product.

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0, <6.34.0, <7.2026.1 allows an attacker to mislead the administrator to change the admin pa
Feb 18, 20267.335NOYES
A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacker to leak the admin gfresttoken
Jun 24, 20267.329NONO
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Cod
Oct 8, 20248.423NONO
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Li
Nov 15, 20236.120NONO
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modules) allows Sensitive credentials posted in plain-text on the
Sep 11, 20246.719NONO
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects P
Sep 11, 20246.118NONO
CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : Remote Code Inclusion.This issu
Apr 1, 20255.417NONO
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in Payara Platform Payara Server (Grizzly, REST Management Interface mod
Jan 21, 20252.412NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA8 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local2 (25.0%)
Network5 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required4 (50.0%)
Privileges Required
Low2 (25.0%)
High3 (37.5%)
None3 (37.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
12.5% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Payara as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Payara as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs