Jakarta Faces 4.1+ utility library
100%
Total Score
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-329430 New omnifaces is vulnerable to Missing Authorization in versions 2.3.0 - 2.7.32, 3.0.0 - 3.14.22, 4.0.0 - 4.7.11 and 5.0.0 - 5.4.1. | 2.3.0 - 2.7.323.0.0 - 3.14.224.0.0 - 4.7.11 +1 more | Medium |
AIKIDO-2026-215809 New omnifaces is vulnerable to Missing Authorization in versions 5.2.0 - 5.4.2. | 5.2.0 - 5.4.2 | Medium |
AIKIDO-2026-553599 New omnifaces is vulnerable to Cross-Site Scripting (XSS) in versions 3.2.0 - 3.14.22, 4.0.0 - 4.7.11 and 5.0.0 - 5.4.1. | 3.2.0 - 3.14.224.0.0 - 4.7.115.0.0 - 5.4.1 | Medium |
AIKIDO-2026-992023 New omnifaces is vulnerable to Uncontrolled Resource Consumption in versions 3.1.0 - 3.14.22, 4.0.0 - 4.7.11 and 5.0.0 - 5.4.1. | 3.1.0 - 3.14.224.0.0 - 4.7.115.0.0 - 5.4.1 | Medium |
CVE-2026-41883 org.omnifaces:omnifaces is vulnerable to Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') in versions 0.0.0 - 1.14.2, 2.0-RC1 - 2.7.32, 3.0-RC1 - 3.14.16, 4.0-M1 - 4.7.5 and 5.0-M1 - 5.2.2. | 0.0.0 - 1.14.22.0-RC1 - 2.7.323.0-RC1 - 3.14.16 +2 more | High |
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant