playframework CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

playframework vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to playframework, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2014-3630 XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data. [email protected] 9.8 0.75% 2017-12-29 2026-05-13
CVE-2015-2156 Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters. [email protected] 7.5 3.27% 2017-10-18 2026-05-13
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence