Vulnerabilities in Lucee
5 resultsVexday analysis
O Lucee apresenta apenas 2 CVEs catalogadas, nenhuma ativa sob ataque e sem críticas, indicando risco limitado no curto prazo. A fraqueza dominante é CWE-79 (Cross-site Scripting), padrão em aplicações web, sem evidência de exploração em campanha. Nenhuma vulnerabilidade foi divulgada nos últimos 90 dias, sugerindo que o risco não é emergente.
CVE-2021-21307HIGHRemote Code Exploit in Lucee AdminEPSS 89.2%CVE-2023-38693CRITICALRCE in Lucee REST endpointEPSS 0.8%CVE-2026-29519MEDIUMLucee CFML Server Reflected XSS via URL Path ParsingEPSS 0.4%CVE-2023-53880MEDIUMLucee 5.4.2.17 Authenticated Reflected Cross-Site Scripting via Admin InterfacesEPSS 0.3%CVE-2024-55354HIGHLucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism faiEPSS 0.2%