Codelibs develops Fess, an open-source enterprise search platform built on Elasticsearch, where disclosures cluster around XML external entity injection and permission-assignment weaknesses characteristic of Java-based search and indexing infrastructure. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codelibs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000822CRITICAL codelibs fess version before commit faa265b contains a XML External Entity (XXE) vulnerability in GSA XML file parser that can result in Disclosure of confidential data, denial of | Dec 20, 2018 | 10.0 | 29 | NO | NO |
CVE-2025-48382MEDIUM Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fess.helper.SystemHelper creates temporary files without explic | May 27, 2025 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codelibs.
Media articles that mention a CVE ID that affects a product developed by Codelibs — matched by CVE ID, not by vendor name.