Play Framework
Vendor:
First CVE: Oct 18, 2017 · Active for 8 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Play Framework over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2017
8 years ago
Most Recent CVE
Jun 2, 2022
1,514 days ago
CVE Severity & Scoring
Play Framework11 CVEs
9%
9%
73%
9%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low0 (0.0%)
High1 (9.1%)
None10 (90.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-3630CRITICAL XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, c | Dec 29, 2017 | 9.8 | 31 | NO | NO |
CVE-2018-13864HIGH A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote at | Jul 17, 2018 | 7.5 | 25 | NO | NO |
CVE-2022-31023HIGH Play Framework is a web framework for Java and Scala. Verions prior to 2.8.16 are vulnerable to generation of error messages containing sensitive information. Play Framework, when | Jun 2, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-31018HIGH Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 through 2.8.15 of Play's forms library, in both the Sca | Jun 2, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-27196HIGH An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON struc | Nov 6, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-26883HIGH In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents. | Nov 6, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-26882HIGH In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input. | Nov 6, 2020 | 7.5 | 24 | NO | NO |
CVE-2019-17598HIGH An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under | Nov 5, 2019 | 7.5 | 23 | NO | NO |
CVE-2015-2156HIGH Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to by | Oct 18, 2017 | 7.5 | 23 | NO | NO |
CVE-2020-12480MEDIUM In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed. | Aug 17, 2020 | 6.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Play Framework
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.3.8 | 1 | 7.5 | 5.4% | 0 | 0 |
| 2.3.7 | 1 | 7.5 | 5.4% | 0 | 0 |
| 2.3.6 | 1 | 7.5 | 5.4% | 0 | 0 |
| 2.3.5 | 1 | 7.5 | 5.4% | 0 | 0 |
| 2.3.4 | 2 | 8.7 | 4.2% | 0 | 0 |
| 2.3.3 | 2 | 8.7 | 4.2% | 0 | 0 |
| 2.3.2 | 2 | 8.7 | 4.2% | 0 | 0 |
| 2.3.1 | 2 | 8.7 | 4.2% | 0 | 0 |
| 2.3.0 | 2 | 8.7 | 4.2% | 0 | 0 |
| 2.2.6 | 1 | 7.5 | 5.4% | 0 | 0 |
| 2.2.2 | 2 | 8.7 | 4.2% | 0 | 0 |
| 2.2.1 | 2 | 8.7 | 4.2% | 0 | 0 |
| 2.2.0 | 2 | 9.3 | 3.4% | 0 | 0 |
| 2.1.1 | 1 | 7.5 | 5.4% | 0 | 0 |
| 2.1.0 | 1 | 7.5 | 5.4% | 0 | 0 |
| 2.0.8 | 1 | 7.5 | 5.4% | 0 | 0 |
| 2.0.7 | 1 | 7.5 | 5.4% | 0 | 0 |
| 2.0.6 | 1 | 7.5 | 5.4% | 0 | 0 |
| 2.0.5 | 1 | 7.5 | 5.4% | 0 | 0 |
| 2.0.4 | 1 | 7.5 | 5.4% | 0 | 0 |