Primetek develops PrimeFaces, a widely adopted Java-based UI component library for web applications, with a vulnerability profile centered on application-layer input-handling and cryptographic practices. The recurring weakness classes—cross-site scripting and inadequate encryption strength—reflect the web-facing nature and data-protection demands of a client-side component framework. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Primetek over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000486CRITICAL Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution | Jan 3, 2018 | 9.8 | 99 | YES | YES |
CVE-2020-10544MEDIUM An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field wh | Mar 13, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Primetek.
Media articles that mention a CVE ID that affects a product developed by Primetek — matched by CVE ID, not by vendor name.