Building the Lucee Loader JAR
89%
Total Score
100
67
80
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10156 lucee is vulnerable to XML External Entity (XXE) Attack in versions 0.0.1 - 5.3.7.58, 5.3.8.132-RC - 5.3.12.0 and 5.4.0.65-RC - 5.4.3.1. | 0.0.1 - 5.3.12.05.4.0.65-RC - 5.4.3.1 | Critical |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.apache.felix:org.apache.felix.framework Version 7.0.5 | — | — |
javax.servlet:javax.servlet-api Version 4.0.1 | — | — |
javax.servlet.jsp:javax.servlet.jsp-api Version 2.3.3 | — | — |
javax.el:javax.el-api Version 3.0.0 | — | — |
org.apache.ant:ant Version 1.10.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant