Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-43142

30
FAUCET Score

CVE-2021-43142 is a critical XML External Entity (XXE) vulnerability affecting wuta jox version 1.16, specifically within the readObject method of JOXSAXBeanInput. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to remotely execute arbitrary code, access sensitive data, or cause denial of service with low attack complexity. While the vulnerability is severe, there is currently no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding it.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.16CPE matchmatch criteria
cpe:2.3:a:jox_project:jox:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.43%
Probability of exploitation in next 30 days
EPSS Percentile
70.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0143 is in the 57th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

mavenGHSA-fcrx-8829-jpqxmedium

Improper Restriction of XML External Entity Reference in wutka jox

Apr 1, 2022

References

novysodope.github.io / 2021/10/29/64
ExploitThird Party Advisory