vciy

CVEs we hold for Vaadin

Records whose assigning authority named Vaadin as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-7860Possible information disclosure of environment variables in Vaadin Build Plugins via Failed Frontend Buildvaadin flow
CVE-2026-2742Unauthorized session creation via reserved framework path accessvaadin; vaadin flow
CVE-2026-2741Zip Slip Path Traversal on Node Unpackvaadin; vaadin flow
CVE-2025-9467Possibility to bypass file upload validation on the server-sidevaadin; vaadin framework; vaadin-upload-flow
CVE-2025-15022Cross-site scripting in Action captionvaadin; vaadin framework; vaadin-spreadsheet-flow
CVE-2023-25500no title heldvaadin; flow-server
CVE-2023-25499Possible information disclosure in non visible componentsvaadin; vaadin flow-server
CVE-2022-29567Possible information disclosure inside TreeGrid component with default data providervaadin; vaadin-grid-flow
CVE-2021-33611Reflected cross-site scripting in vaadin-menu-bar webjar resources in Vaadin 14Vaadin; vaadin-menu-bar
CVE-2021-33609Denial of service in DataCommunicator class in Vaadin 8Vaadin; vaadin-server
CVE-2021-33605Unauthorized property update in CheckboxGroup component in Vaadin 12-14 and 15-20Vaadin; vaadin-checkbox-flow
CVE-2021-33604Reflected cross-site scripting in development mode handler in Vaadin 14, 15-19Vaadin; Vaadin flow-server
CVE-2021-31412Possible route enumeration in production mode via RouteNotFoundError view in Vaadin 10, 11-14, and 15-19Vaadin; Vaadin flow-server
CVE-2021-31411Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-19Vaadin; Vaadin flow-server
CVE-2021-31410Project sources exposure in Vaadin DesignerVaadin Designer
CVE-2021-31409Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19Vaadin; vaadin-compatibility-server
CVE-2021-31408Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19Vaadin; Vaadin flow-client
CVE-2021-31407Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19Vaadin; Vaadin flow-server
CVE-2021-31406Timing side channel vulnerability in endpoint request handler in Vaadin 15-19Vaadin; Vaadin flow-server
CVE-2021-31405Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17Vaadin; vaadin-text-field-flow
CVE-2021-31404Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18Vaadin; Vaadin flow-server
CVE-2021-31403Timing side channel vulnerability in UIDL request handler in Vaadin 7 and 8Vaadin; vaadin-server
CVE-2020-36321Directory traversal in development mode handler in Vaadin 14 and 15-17Vaadin; Vaadin flow-server
CVE-2020-36320Regular expression Denial of Service (ReDoS) in EmailValidator class in Vaadin 7Vaadin; vaadin-server
CVE-2020-36319Potential sensitive data exposure in applications using Vaadin 15Vaadin; Vaadin flow-server
CVE-2019-25028Stored cross-site scripting in Grid component in Vaadin 7 and 8Vaadin; vaadin-server
CVE-2019-25027Reflected cross-site scripting in default RouteNotFoundError view in Vaadin 10 and 11-13Vaadin; Vaadin flow-server
CVE-2018-25007Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11Vaadin; Vaadin flow-server

28 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.