Payara maintains a focused open-source Java application server product line that, despite limited product scope, occupies a visible position in enterprise middleware deployments and frequently attracts security research attention. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a pronounced tendency to acquire public exploit code, while the recurring weaknesses—path traversal, cross-site scripting, open redirect, untrusted deserialization, and improper file access controls—reflect both the web-facing tier and object-serialization complexities inherent to Java middleware. Defenders should treat Payara disclosures as high-priority for affected infrastructure; live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Payara over time
Of all the CVEs published by Payara as a CNA, 50.0% affect products that Payara develops as a vendor.
Of all the CVEs published that affect products developed by Payara, 50.0% are self-published by Payara as a CNA.
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41381HIGH Payara Micro Community 5.2021.6 and below allows Directory Traversal. | Sep 23, 2021 | 7.5 | 72 | NO | YES |
CVE-2023-28462CRITICAL A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 an | Mar 30, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-37422HIGH Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded. | Aug 18, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-45129HIGH Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Plat | Nov 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2024-8215HIGH Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Cod | Oct 8, 2024 | 8.4 | 23 | NO | NO |
CVE-2023-41699MEDIUM URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Li | Nov 15, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-7312MEDIUM URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects P | Sep 11, 2024 | 6.1 | 18 | NO | NO |
CVE-2025-1534MEDIUM CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : Remote Code Inclusion.This issu | Apr 1, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Payara.
Media articles that mention a CVE ID that affects a product developed by Payara — matched by CVE ID, not by vendor name.