Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vaadin Ltd.

First CVE: Jan 20, 2011Active for: 16 yearsTotal CVEs: 27
16.2
VTI Score
Low

Vaadin Ltd. maintains a focused web-application framework and tooling portfolio, principally the Vaadin framework and its Flow server implementation, that sits in the development and runtime layers of enterprise web applications. The vendor's vulnerability profile concentrates in information-disclosure and input-handling weakness classes—including sensitive-information exposure, cross-site scripting, resource-consumption issues, and exposure across trust boundaries—that reflect the parsing and rendering demands of a web-UI framework handling untrusted input. These disclosures span a narrow product range but reach a prominent position in the landscape owing to the framework's embedded presence in downstream applications, meaning individual Vaadin flaws propagate across organizations that have built systems on it. Defenders should track Vaadin advisories and incorporate them into application-dependency reviews rather than infrastructure scanning; current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vaadin Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 20, 2011
15 years ago
Most Recent CVE
May 19, 2026
66 days ago

Self-Reporting Analysis

Of all the CVEs published by Vaadin Ltd. as a CNA, 92.9% affect products that Vaadin Ltd. develops as a vendor.

92.9%
Self-reported: 26 (92.9%)
Third-party: 2 (7.1%)

Of all the CVEs published that affect products developed by Vaadin Ltd., 96.3% are self-published by Vaadin Ltd. as a CNA.

96.3%
Self-published: 26 (96.3%)
Other CNAs: 1 (3.7%)

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-2741MEDIUM
Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Vaadin 14.2.0 through 14.14.0, 15.0.0 through 23.6.6, 24.0.0 t
Mar 10, 20266.823NONO
CVE-2022-29567HIGH
The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14
May 24, 20227.523NONO
CVE-2021-31409HIGH
Unsafe validation RegEx in EmailValidator component in com.vaadin:vaadin-compatibility-server versions 8.0.0 through 8.12.4 (Vaadin versions 8.0.0 through 8.12.4) allows attackers
May 6, 20217.523NONO
CVE-2021-31410HIGH
Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project sources via crafted HTTP request
Apr 23, 20217.523NONO
CVE-2021-31411HIGH
Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (V
May 5, 20217.822NONO
CVE-2021-31407HIGH
Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to
Apr 23, 20217.522NONO
CVE-2021-31405HIGH
Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15
Apr 23, 20217.522NONO
CVE-2020-36321HIGH
Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to
Apr 23, 20217.522NONO
CVE-2020-36320HIGH
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resou
Apr 23, 20217.522NONO
CVE-2020-36319MEDIUM
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application al
Apr 23, 20216.522NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
19%
48%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local7 (25.9%)
Network19 (70.4%)
Unknown1 (3.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (74.1%)
High6 (22.2%)
Unknown1 (3.7%)
User Interaction
None20 (74.1%)
Unknown1 (3.7%)
Required5 (18.5%)
Privileges Required
Low11 (40.7%)
High0 (0.0%)
None15 (55.6%)
Unknown1 (3.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vaadin Ltd..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vaadin Ltd. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vaadin Ltd.'s Products

View all 2 CNAs →

Top CWEs