com.vaadin:vaadin-server
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.vaadin:vaadin-serverpage 1 of 1
- CVE-2019-25028MEDIUMCVSS 5.4EG 5.4✓ Fixed in 8.8.52021-04-23
vulnerable: 8.0.0 ... 8.8.4 (46 versions)
Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 through 7.7.19), and 8.0.0 through 8.8.4 (Vaadin 8.0.0 through 8.8.4) allows attacker to inject malicious JavaScript vi…
- CVE-2020-36320HIGHCVSS 7.5EG 7.5✓ Fixed in 7.7.222021-04-23
vulnerable: 7.0.0 ... 7.7.9 (136 versions)
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
- CVE-2021-31403MEDIUMCVSS 4.0EG 4.0✓ Fixed in 8.12.32021-04-23
vulnerable: 8.0.0 ... 8.9.4 (66 versions)
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7.7.23 (Vaadin 7.0.0 through 7.7.23), and 8.0.0 through 8.12.2 (Vaadin 8.0.0 through 8.12.2) allows attacker to guess a …
- CVE-2021-33609MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.14.12021-10-13
vulnerable: 8.0.6 ... 8.9.4 (67 versions)
Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.
- CVE-2025-15022MEDIUMCVSS 4.8EG 0.0✓ Fixed in 8.30.02026-01-05
vulnerable: 8.0.0 ... 8.9.4 (111 versions)
Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS) if caption content is derived from user input. In Vaadin Framework 7 and 8, the Action class is a general-purpose cla…
- CVE-2025-9467MEDIUMCVSS 5.3EG 0.0✓ Fixed in 8.28.22025-09-04
vulnerable: 8.0.0 ... 8.9.4 (107 versions)
When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of affected versions should apply the following mitigation or upgrade. Releases that ha…
Check whether com.vaadin:vaadin-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.vaadin:vaadin-server CVEs against the assets you own.
Start Free Scan →