← Back

Vaadin

vaadin

26 CVEs • 6 products

Products (6)

Click to collapse
Toggle
Vaadin
vaadin
Flow
flow
Designer
designer
Flow Server
flow-server

CVEs (26)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vaadin
1Vaadin
Jun 17, 2026
Apr 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resource consumption by submitting malicious...Show more
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.Show less
1Vaadin
2Flow
Vaadin
Jun 17, 2026
Apr 23, 2021
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController
1Vaadin
1Vaadin
Jun 17, 2026
Apr 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 through 7.7.19), and 8.0.0 through 8.8.4 (Vaadin 8.0.0 through 8.8.4) allows attacker to inject mali...Show more
Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 through 7.7.19), and 8.0.0 through 8.8.4 (Vaadin 8.0.0 through 8.8.4) allows attacker to inject malicious JavaScript via unspecified vectorShow less
1Vaadin
2Flow
Vaadin
Jun 17, 2026
Apr 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attack...Show more
Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attacker to execute malicious JavaScript via crafted URLShow less
1Vaadin
2Flow
Vaadin
Nov 21, 2024
Apr 23, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0.7, and 11.0.0 through 11.0.2) allows attacker to update element property values via crafted synchro...Show more
Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0.7, and 11.0.0 through 11.0.2) allows attacker to update element property values via crafted synchronization message.Show less
1Vaadin
1Vaadin
Apr 29, 2026
Jan 20, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Vaadin before 6.4.9 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the index page.