Vaadin / Flow
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-7860 | Possible information disclosure of environment variables in Vaadin Build Plugins via Failed Frontend Build | LOW | 1.6 | May 19, 2026 |
| CVE-2026-2742 | Unauthorized session creation via reserved framework path access | MEDIUM | 5.3 | Mar 10, 2026 |
| CVE-2026-2741 | Zip Slip Path Traversal on Node Unpack | LOW | 2.3 | Mar 10, 2026 |
| CVE-2021-31412 | Possible route enumeration in production mode via RouteNotFoundError view in Vaadin 10, 11-14, and 15-19 | MEDIUM | 5.3 | Jun 24, 2021 |
| CVE-2021-31411 | Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-19 | HIGH | 7.8 | May 5, 2021 |
| CVE-2021-31408 | Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19 | HIGH | 7.1 | Apr 23, 2021 |
| CVE-2021-31407 | Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19 | HIGH | 8.6 | Apr 23, 2021 |
| CVE-2021-31406 | Timing side channel vulnerability in endpoint request handler in Vaadin 15-19 | MEDIUM | 4.0 | Apr 23, 2021 |
| CVE-2021-31405 | Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17 | HIGH | 7.5 | Apr 23, 2021 |
| CVE-2021-31404 | Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18 | MEDIUM | 4.0 | Apr 23, 2021 |
| CVE-2020-36321 | Directory traversal in development mode handler in Vaadin 14 and 15-17 | HIGH | 7.5 | Apr 23, 2021 |
| CVE-2020-36319 | Potential sensitive data exposure in applications using Vaadin 15 | MEDIUM | 6.5 | Apr 23, 2021 |
| CVE-2019-25027 | Reflected cross-site scripting in default RouteNotFoundError view in Vaadin 10 and 11-13 | MEDIUM | 6.1 | Apr 23, 2021 |
| CVE-2018-25007 | Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11 | MEDIUM | 4.3 | Apr 23, 2021 |
Showing 1 to 14 of 14 CVEs