Haulmont maintains a focused set of enterprise application frameworks and platforms, including Cuba Platform and Jmix Framework, with a vulnerability footprint centered on web-facing input-handling and access-control issues such as cross-site scripting, path traversal, and resource-exhaustion weaknesses. These weakness classes reflect the web application and API layer where these frameworks operate; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Haulmont over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-32952MEDIUM Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the local file storage implementat | Apr 22, 2025 | 6.5 | 20 | NO | NO |
CVE-2018-20663MEDIUM The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "Reports > Reports" name field. | Jan 3, 2019 | 5.4 | 20 | NO | NO |
CVE-2025-32950MEDIUM Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, attackers could manipulate the Fil | Apr 22, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-32951MEDIUM Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the input parameter, which consist | Apr 22, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Haulmont.
Media articles that mention a CVE ID that affects a product developed by Haulmont — matched by CVE ID, not by vendor name.