Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vaadin MEDIUM 5.3
CVE-2026-2742

An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.…

Fix: 14.14.1 / 23.6.7+
Fix from $1,600 2026-03-10
Vaadin MEDIUM 6.8
CVE-2026-2741

Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Vaadin 14.2.0 through 14.14.0, …

Fix: 14.14.1 / 23.6.7+
Fix from $1,600 2026-03-10
Vaadin MEDIUM 6.5
CVE-2023-25499

When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0,…

Fix: 10.0.23 / 14.10.1+
Fix from $1,600 2023-06-22
Vaadin HIGH 7.5
CVE-2022-29567

The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through…

Fix: after 23.0.8
Fix from $1,950 2022-05-24
Vaadin MEDIUM 6.1
CVE-2021-33611

Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.…

Fix: after 14.4.4
Fix from $1,600 2021-11-02
Flow MEDIUM 5.3
CVE-2021-31412

Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14 (Vaadin 10.0.0 through 10.0.…

Fix: after 19.0.8
Fix from $1,600 2021-06-24
Vaadin HIGH 7.5
CVE-2021-31409

Unsafe validation RegEx in EmailValidator component in com.vaadin:vaadin-compatibility-server versions 8.0.0 through 8.12.4 (Vaadin versions 8.0.0 th…

Fix: after 8.12.4
Fix from $1,950 2021-05-06
Flow HIGH 7.8
CVE-2021-31411

Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaad…

Fix: 2.5.3 / 14.5.3+
Fix from $1,950 2021-05-05
Designer HIGH 7.5
CVE-2021-31410

Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project s…

Fix: 4.6.4+
Fix from $1,950 2021-04-23
Flow HIGH 7.1
CVE-2021-31408

Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19…

Fix: 6.0.0 / 6.0.5+
Fix from $1,950 2021-04-23
Vaadin HIGH 7.5
CVE-2020-36320

Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attack…

Fix: 7.7.22+
Fix from $1,950 2021-04-23
Flow HIGH 7.5
CVE-2020-36321

Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 pr…

Fix: 2.4.2 / 5.0.0+
Fix from $1,950 2021-04-23
Flow HIGH 7.5
CVE-2021-31405

Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and…

Fix: 2.3.3 / 4.0.3+
Fix from $1,950 2021-04-23
Flow HIGH 7.5
CVE-2021-31407

Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaa…

Fix: 2.4.8 / 6.0.2+
Fix from $1,950 2021-04-23
Flow MEDIUM 6.5
CVE-2020-36319

Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensi…

Fix: 3.0.6 / 15.0.5+
Fix from $1,600 2021-04-23
Vaadin MEDIUM 6.1
CVE-2019-25028

Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 through 7.7.19), and 8.0.0 th…

Fix: 7.7.20 / 8.8.5+
Fix from $1,600 2021-04-23
Flow MEDIUM 6.1
CVE-2019-25027

Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13…

Fix: 1.0.11 / 1.4.3+
Fix from $1,600 2021-04-23