CVE-2025-1534: Cross-site Scripting (Stored)
CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : Remote Code Inclusion.This issue affects Payara Server: from 4.1.2.1919.1 before 4.1.2.191.51, from 5.20.0 before 5.68.0, from 6.0.0 before 6.23.0, from 6.2022.1 before 6.2025.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1534?
CVE-2025-1534 has a high severity rating due to its potential for Remote Code Inclusion.
How do I fix CVE-2025-1534?
To mitigate CVE-2025-1534, upgrade Payara Server to version 4.1.2.191.51 or later, 5.68.0 or later, or 6.23.0 or later.
Which versions of Payara Server are affected by CVE-2025-1534?
CVE-2025-1534 affects Payara Server versions from 4.1.2.1919.1 to 4.1.2.191.51, 5.20.0 to 5.68.0, and 6.0.0 to 6.23.0.
What type of vulnerability is CVE-2025-1534?
CVE-2025-1534 is an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability.
Can CVE-2025-1534 lead to data breaches?
Yes, CVE-2025-1534 can potentially lead to data breaches through Remote Code Inclusion if exploited.