Lucee Server Lucee Server

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Lucee Server.

By the Year

In 2025 there have been 2 vulnerabilities in Lucee Server. Lucee Server did not have any published security vulnerabilities last year. That is, 2 more vulnerabilities have already been reported in 2025 as compared to last year.

Year Vulnerabilities Average Score
2025 2 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 1 9.80
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Lucee Server vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Lucee Server Security Vulnerabilities

Lucee Vulnerability April 2025

CVE-2024-55354 - April 08, 2025

Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism failure that can let an attacker run code that would be expected to be blocked and access resources that would be expected to be protected.

Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development

CVE-2023-38693 - March 05, 2025

Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development. The Lucee REST endpoint is vulnerable to RCE via an XML XXE attack. This vulnerability is fixed in Lucee 5.4.3.2, 5.3.12.1, 5.3.7.59, 5.3.8.236, and 5.3.9.173.

XXE

Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development

CVE-2021-21307 9.8 - Critical - February 11, 2021

Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.

AuthZ

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Lucee Server or by Lucee? Click the Watch button to subscribe.

Lucee
Vendor

Lucee Server
Product

subscribe