Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Vaadin — Vulnerabilities & Security Advisories 30

Browse all 30 CVE security advisories affecting Vaadin. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Vaadin is a Java framework primarily used for building modern web applications, enabling developers to create rich user interfaces through server-side rendering. With twenty-seven recorded Common Vulnerabilities and Exposures, the platform has historically faced issues ranging from cross-site scripting and server-side request forgery to privilege escalation and remote code execution. These flaws often stem from improper input validation, insecure deserialization, and inadequate access controls within the framework’s core components. While Vaadin employs standard security practices, its complexity and extensive feature set have occasionally introduced attack surfaces that attackers exploit to gain unauthorized access or execute malicious commands. Recent updates have addressed several critical paths, yet the persistent vulnerability count highlights the ongoing challenge of maintaining robust security in complex enterprise-grade software ecosystems.

Top products by Vaadin: Vaadin Designer flow
CVE ID Title CVSS Severity Published
CVE-2026-93547 Missing Authorization Check in Vaadin Spreadsheet Allows Cell Comments to Be Written to Protected Sheets and Locked Cells — vaadin CWE-285 5.3 Medium 2026-09-30
CVE-2026-91860 Prototype Pollution in Vaadin Charts and Component Base via Unfiltered Deep Merge — vaadin CWE-1321 6.3 Medium 2026-09-30
CVE-2026-7860 Possible information disclosure of environment variables in Vaadin Build Plugins via Failed Frontend Build — flow CWE-209 1.6 Low 2026-05-19
CVE-2026-2742 Unauthorized session creation via reserved framework path access — vaadin CWE-284 9.1AI Critical AI 2026-03-10
CVE-2026-2741 Zip Slip Path Traversal on Node Unpack — vaadin CWE-22 6.7AI Medium AI 2026-03-10
CVE-2025-15022 Cross-site scripting in Action caption — vaadin CWE-79 6.1 - 2026-01-05
CVE-2025-9467 Possibility to bypass file upload validation on the server-side — vaadin CWE-20 5.3 Medium 2025-09-04
CVE-2023-25500 Vaadin 信息泄露漏洞 — vaadin CWE-200 3.5 Low 2023-06-22
CVE-2023-25499 Possible information disclosure in non visible components — vaadin CWE-200 5.7 Medium 2023-06-22
CVE-2022-29567 Possible information disclosure inside TreeGrid component with default data provider — vaadin CWE-200 5.7 Medium 2022-05-24
CVE-2021-33611 Reflected cross-site scripting in vaadin-menu-bar webjar resources in Vaadin 14 — Vaadin CWE-79 6.1 Medium 2021-11-02
CVE-2021-33609 Denial of service in DataCommunicator class in Vaadin 8 — Vaadin CWE-400 4.3 Medium 2021-10-13
CVE-2021-33605 Unauthorized property update in CheckboxGroup component in Vaadin 12-14 and 15-20 — Vaadin CWE-754 4.3 Medium 2021-08-25
CVE-2021-31412 Possible route enumeration in production mode via RouteNotFoundError view in Vaadin 10, 11-14, and 15-19 — Vaadin CWE-1295 5.3 Medium 2021-06-24
CVE-2021-33604 Reflected cross-site scripting in development mode handler in Vaadin 14, 15-19 — Vaadin CWE-172 2.5 Low 2021-06-24
CVE-2021-31409 Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19 — Vaadin CWE-400 7.5 High 2021-05-05
CVE-2021-31411 Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-19 — Vaadin CWE-379 6.3 Medium 2021-05-05
CVE-2021-31410 Project sources exposure in Vaadin Designer — Designer CWE-402 8.6 High 2021-04-23
CVE-2021-31408 Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19 — Vaadin CWE-613 6.3 Medium 2021-04-23
CVE-2021-31407 Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19 — Vaadin CWE-402 8.6 High 2021-04-23
CVE-2021-31406 Timing side channel vulnerability in endpoint request handler in Vaadin 15-19 — Vaadin CWE-208 4.0 Medium 2021-04-23
CVE-2021-31405 Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17 — Vaadin CWE-400 7.5 High 2021-04-23
CVE-2021-31404 Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18 — Vaadin CWE-208 4.0 Medium 2021-04-23
CVE-2021-31403 Timing side channel vulnerability in UIDL request handler in Vaadin 7 and 8 — Vaadin CWE-208 4.0 Medium 2021-04-23
CVE-2020-36321 Directory traversal in development mode handler in Vaadin 14 and 15-17 — Vaadin CWE-22 5.9 Medium 2021-04-23
CVE-2020-36320 Regular expression Denial of Service (ReDoS) in EmailValidator class in Vaadin 7 — Vaadin CWE-400 7.5 High 2021-04-23
CVE-2020-36319 Potential sensitive data exposure in applications using Vaadin 15 — Vaadin CWE-200 3.1 Low 2021-04-23
CVE-2019-25028 Stored cross-site scripting in Grid component in Vaadin 7 and 8 — Vaadin CWE-80 5.4 Medium 2021-04-23
CVE-2018-25007 Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11 — Vaadin CWE-754 2.6 Low 2021-04-23
CVE-2019-25027 Reflected cross-site scripting in default RouteNotFoundError view in Vaadin 10 and 11-13 — Vaadin CWE-81 6.1 Medium 2021-04-23

This page lists every published CVE security advisory associated with Vaadin. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.