com.vaadin:vaadin
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.vaadin:vaadinpage 1 of 1
- CVE-2022-29567MEDIUMCVSS 5.7EG 5.7✓ Fixed in 23.0.92022-05-24
vulnerable: 23.0.0 ... 23.0.8 (9 versions)
The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.…
- CVE-2023-25499MEDIUMCVSS 5.7EG 5.7✓ Fixed in 24.1.02023-06-22
When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1 t…
- CVE-2023-25500LOWCVSS 3.5EG 3.5✓ Fixed in 24.1.02023-06-22
Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in…
- CVE-2025-15022MEDIUMCVSS 4.8EG 0.0✓ Fixed in 24.9.72026-01-05
vulnerable: 24.9.0 ... 24.9.6 (7 versions)
Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS) if caption content is derived from user input. In Vaadin Framework 7 and 8, the Action class is a general-purpose cla…
- CVE-2026-2742MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.14.12026-03-10
vulnerable: 10.0.0 ... 7.0.0.alpha3 (302 versions)
An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.1, applications using Spring Security due to inconsistent path pattern matching of reserv…
Check whether com.vaadin:vaadin is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.vaadin:vaadin CVEs against the assets you own.
Start Free Scan →