Payara
CVE Numbering Authority
Latest CVE published
Overview
Payara is a CVE Numbering Authority that has published 6 CVE records since 2023. It is currently classified as active, with 5 CVEs published in the last two years. Its CVE data quality is graded A (100% overall completeness).
Among the 370 CNAs tracked here, Payara ranks #343 by CVE volume and reports more complete records than 60% of all CNAs.
Data quality report card
How complete and consistent Payara's CVE records are, scored across vendor, product, CVSS, and CWE coverage.
A CVE record only requires a description to be published. “Completeness” measures how often Payara also fills in the optional — but extremely useful — fields that make a vulnerability actually actionable: the affected vendor and product, a CVSS severity score, and a CWE weakness type. A higher score means more of this CNA’s CVEs include those details, so defenders spend less time enriching records by hand.
Report card grade
100%
Overall score
What these scores mean
- Vendor completeness
- The share of this CNA's CVEs that name an affected vendor.
- Product completeness
- The share that name a specific affected product.
- CVSS completeness
- The share that include a CVSS severity score.
- CWE completeness
- The share mapped to a CWE weakness type.
- Update rate
- How often this CNA revises CVE records after first publishing them.
- Vendor diversity
- How many distinct vendors this CNA publishes CVEs for.
Severity and exploitation
How the CVSS severity of Payara's published CVEs breaks down, and how many are known to be exploited in the wild.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of Payara's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Common weakness types
The CWE weakness categories Payara most often assigns to its CVEs. Follow any weakness to its full explanation.
- CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3 CVEs
- CWE-601URL Redirection to Untrusted Site ('Open Redirect')2 CVEs
- CWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')1 CVE
- CWE-200Exposure of Sensitive Information to an Unauthorized Actor1 CVE
- CWE-352Cross-Site Request Forgery (CSRF)1 CVE
Publishing activity by year
How many CVEs Payara has published each year.
Top vendors
The vendors Payara publishes the most CVEs for.
- Payara Platform7 CVEs
- Payara5 CVEs
Top products
The products Payara publishes the most CVEs for.
- Payara Server7 CVEs
- payara4 CVEs
- Payara Micro1 CVEs
- Payara Server, Micro and Embedded1 CVEs
Latest CVEs
The most recent CVEs assigned by Payara.
- CVE-2026-12986CWE-352High · CVSS 7.3EPSS 0.3%2026-06-24
- CVE-2025-14340CWE-79
Admin Account Takeover via malicious URL payload
High · CVSS 7.3EPSS 1.0%2026-02-18 - CVE-2025-1534CWE-79
Cross-site Scripting (Stored)
Medium · CVSS 6.8EPSS 0.3%2025-04-01 - CVE-2024-45687CWE-113Low · CVSS 2.4EPSS 0.2%2025-01-21
- CVE-2024-8215CWE-79High · CVSS 8.7EPSS 0.4%2024-10-08
- CVE-2024-8097CWE-200
Sensitive information exposure when the org.glassfish.admingui LOGGER is set to FINEST level
Medium · CVSS 6.7EPSS 0.2%2024-09-11 - CVE-2024-7312CWE-601High · CVSS 7.0EPSS 0.2%2024-09-11
- CVE-2023-41699CWE-601Medium · CVSS 6.1EPSS 0.4%2023-11-15
Track new Payara CVEs as they are published and get AI-written analysis and remediation guidance.
Monitor Payara CVEsOther CNAs
Compare data quality across other CVE Numbering Authorities.
Frequently asked questions
Common questions about the Payara CNA.
- What is the Payara CNA?
- Payara is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 6 CVE records since 2023.
- How many CVEs has Payara published?
- Payara has published 6 CVE records, including 5 in the last two years.
- What is Payara's CVE data quality grade?
- RadicalNotion.AI grades Payara's CVE data quality as A, with an overall completeness score of 100%. This reflects how consistently its CVE records include vendor (100%), product (100%), CVSS (100%), and CWE (100%) information.
- What products does Payara publish CVEs for?
- Payara most frequently publishes CVEs for Payara Server, payara, Payara Micro, Payara Server, Micro and Embedded.
- Which vendors does Payara cover?
- Payara publishes CVEs across 1 distinct vendors, most often Payara Platform, Payara.
- Is Payara actively publishing CVEs?
- Payara is currently active, based on 5 CVEs in the last two years.
- What is the average severity of Payara's CVEs?
- The average CVSS base score across Payara's scored CVEs is 6.3.
- Are any of Payara's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- No. None of Payara's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- What are the most common weakness types in Payara's CVEs?
- Payara's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')), CWE-113 (Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
- How does Payara rank among CNAs?
- By total CVE volume, Payara ranks #343 of 370 CNAs, and it reports more complete CVE records than 60% of all CNAs.
References
- Official CVE.org list of CNA partners (opens in a new tab)
- Learn: What is a CNA?
- CWE directory: the weakness types this CNA maps its CVEs to
CNA report-card grades are computed by RadicalNotion.AI from published CVE records. CVE data is sourced from the CVE Program.
Track Payara CVEs
Monitor new vulnerabilities as this CNA publishes them, with AI-written analysis and remediation guidance.