CVE-2023-38693: Lucee

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development. The Lucee REST endpoint is vulnerable to RCE via an XML XXE attack. This vulnerability is fixed in Lucee 5.4.3.2, 5.3.12.1, 5.3.7.59, 5.3.8.236, and 5.3.9.173.

Affected products

  • Lucee Lucee: from 5.4.0.0, before 5.4.3.2 (fixed in 5.4.3.2); from 5.3.12.0, before 5.3.12.1 (fixed in 5.3.12.1); before 5.3.7.59 (fixed in 5.3.7.59); from 5.3.8.0, before 5.3.8.236 (fixed in 5.3.8.236); from 5.3.9.0, before 5.3.9.173 (fixed in 5.3.9.173)

Published 2025-03-05. Last modified 2026-06-17.