Vaadin Ltd.

First CVE: Apr 23, 2021Active for: 5 years
28
CVEs Published
More CVEs Published than 47% of tracked CNAs
5.6
Avg CVEs / Year
More Avg CVEs / Year than 36% of tracked CNAs
5.5
Avg CVSS Score
Higher Avg CVSS Score than 5% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Vaadin Ltd. as a CNA, 92.9% affect products that Vaadin Ltd. develops as a vendor.

92.9%
Self-reported: 26Third-party: 2

Of all the CVEs published that affect products developed by Vaadin Ltd., 96.3% are self-published by Vaadin Ltd. as a CNA.

96.3%
Self-published: 26Published by other CNAs: 1

Trends Over Time

The number and severity of CVEs published by Vaadin Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 23, 2021
5 years ago
Most Recent CVE
May 19, 2026
67 days ago

Top CVEs

All CVEs published by Vaadin Ltd. as a CNA, regardless of affected vendor or product.

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Vaadin 14.2.0 through 14.14.0, 15.0.0 through 23.6.6, 24.0.0 t
Mar 10, 20266.823NONO
The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14
May 24, 20227.523NONO
Unsafe validation RegEx in EmailValidator component in com.vaadin:vaadin-compatibility-server versions 8.0.0 through 8.12.4 (Vaadin versions 8.0.0 through 8.12.4) allows attackers
May 6, 20217.523NONO
Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project sources via crafted HTTP request
Apr 23, 20217.523NONO
Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (V
May 5, 20217.822NONO
Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to
Apr 23, 20217.522NONO
Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15
Apr 23, 20217.522NONO
Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to
Apr 23, 20217.522NONO
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resou
Apr 23, 20217.522NONO
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application al
Apr 23, 20216.522NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA28 CVEs
Severity distribution among all CVEs352,427 CVEs
LowMediumHigh
Attack Vector
Local7 (25.0%)
Network21 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (78.6%)
High6 (21.4%)
Unknown0 (0.0%)
User Interaction
None21 (75.0%)
Unknown0 (0.0%)
Required5 (17.9%)
Privileges Required
Low13 (46.4%)
High0 (0.0%)
None15 (53.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Vaadin Ltd. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Vaadin Ltd. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs