Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Payara

First CVE: Sep 23, 2021Active for: 5 yearsTotal CVEs: 8

Payara maintains a focused open-source Java application server product line that, despite limited product scope, occupies a visible position in enterprise middleware deployments and frequently attracts security research attention. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a pronounced tendency to acquire public exploit code, while the recurring weaknesses—path traversal, cross-site scripting, open redirect, untrusted deserialization, and improper file access controls—reflect both the web-facing tier and object-serialization complexities inherent to Java middleware. Defenders should treat Payara disclosures as high-priority for affected infrastructure; live severity, exploitation, and current exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Payara over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2021
4 years ago
Most Recent CVE
Apr 1, 2025
479 days ago

Self-Reporting Analysis

Of all the CVEs published by Payara as a CNA, 50.0% affect products that Payara develops as a vendor.

50.0%
50.0%
Self-reported: 4 (50.0%)
Third-party: 4 (50.0%)

Of all the CVEs published that affect products developed by Payara, 50.0% are self-published by Payara as a CNA.

50.0%
50.0%
Self-published: 4 (50.0%)
Other CNAs: 4 (50.0%)

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-41381HIGH
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
Sep 23, 20217.572NOYES
CVE-2023-28462CRITICAL
A JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 and newer (Community), when Java 1.8u181 an
Mar 30, 20239.829NONO
CVE-2022-37422HIGH
Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.
Aug 18, 20227.526NONO
CVE-2022-45129HIGH
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Plat
Nov 10, 20227.525NONO
CVE-2024-8215HIGH
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Cod
Oct 8, 20248.423NONO
CVE-2023-41699MEDIUM
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Li
Nov 15, 20236.120NONO
CVE-2024-7312MEDIUM
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects P
Sep 11, 20246.118NONO
CVE-2025-1534MEDIUM
CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : Remote Code Inclusion.This issu
Apr 1, 20255.417NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
38%
50%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (50.0%)
Unknown0 (0.0%)
Required4 (50.0%)
Privileges Required
Low1 (12.5%)
High1 (12.5%)
None6 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
1 CVE
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Payara.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Payara — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Payara's Products

View all 2 CNAs →

Top CWEs