Vaadin Ltd. maintains a focused web-application framework and tooling portfolio, principally the Vaadin framework and its Flow server implementation, that sits in the development and runtime layers of enterprise web applications. The vendor's vulnerability profile concentrates in information-disclosure and input-handling weakness classes—including sensitive-information exposure, cross-site scripting, resource-consumption issues, and exposure across trust boundaries—that reflect the parsing and rendering demands of a web-UI framework handling untrusted input. These disclosures span a narrow product range but reach a prominent position in the landscape owing to the framework's embedded presence in downstream applications, meaning individual Vaadin flaws propagate across organizations that have built systems on it. Defenders should track Vaadin advisories and incorporate them into application-dependency reviews rather than infrastructure scanning; current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vaadin Ltd. over time
Of all the CVEs published by Vaadin Ltd. as a CNA, 92.9% affect products that Vaadin Ltd. develops as a vendor.
Of all the CVEs published that affect products developed by Vaadin Ltd., 96.3% are self-published by Vaadin Ltd. as a CNA.
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2741MEDIUM Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Vaadin 14.2.0 through 14.14.0, 15.0.0 through 23.6.6, 24.0.0 t | Mar 10, 2026 | 6.8 | 23 | NO | NO |
CVE-2022-29567HIGH The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14 | May 24, 2022 | 7.5 | 23 | NO | NO |
CVE-2021-31409HIGH Unsafe validation RegEx in EmailValidator component in com.vaadin:vaadin-compatibility-server versions 8.0.0 through 8.12.4 (Vaadin versions 8.0.0 through 8.12.4) allows attackers | May 6, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-31410HIGH Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project sources via crafted HTTP request | Apr 23, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-31411HIGH Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (V | May 5, 2021 | 7.8 | 22 | NO | NO |
CVE-2021-31407HIGH Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to | Apr 23, 2021 | 7.5 | 22 | NO | NO |
CVE-2021-31405HIGH Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15 | Apr 23, 2021 | 7.5 | 22 | NO | NO |
CVE-2020-36321HIGH Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to | Apr 23, 2021 | 7.5 | 22 | NO | NO |
CVE-2020-36320HIGH Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resou | Apr 23, 2021 | 7.5 | 22 | NO | NO |
CVE-2020-36319MEDIUM Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application al | Apr 23, 2021 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vaadin Ltd..
Media articles that mention a CVE ID that affects a product developed by Vaadin Ltd. — matched by CVE ID, not by vendor name.