CVE-2026-29519 Details
Description
Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site scripting vulnerability in URL path parsing that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser by embedding HTML or JavaScript payloads within the request path. Attackers can craft a malicious URL containing injected script content that is reflected in the server's response without proper output encoding, enabling session hijacking or unauthorized actions against the Lucee administrative interface when a victim visits the crafted link.
A reflected cross-site scripting vulnerability has been identified in Lucee CFML Server versions 5.3.x, 6.1.x, 6.2.x, and 7.0.x. This vulnerability arises from improper URL path parsing, allowing unauthenticated remote attackers to execute arbitrary JavaScript in the context of the victim's browser. Attackers can craft malicious URLs that inject HTML or JavaScript payloads, which are then reflected in the server's response without adequate output encoding. This exploitation could lead to session hijacking or unauthorized actions within the Lucee administrative interface when the victim clicks on the malicious link.
Users can upgrade to Lucee versions 6.0.4.10 or 5.4.8.2, both of which are secure. If an upgrade is not possible, a temporary WAF rule can be applied to block HTML tags in URL paths.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/L4V4D0/CVE-2026-29519-Lucee-Reflected-XSS | [email protected] | ExploitTechnical Analysis |
| https://www.vulncheck.com/advisories/lucee-cfml-server-reflected-xss-via-url-path-parsing | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Lucee | >= 5.3.1.95, <= 7.0.0.395 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion