Flow
Vendor:
First CVE: Apr 23, 2021 · Active for 5 years
12
Total CVEs
More Total CVEs than 90% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 15% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Flow over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 23, 2021
5 years ago
Most Recent CVE
May 19, 2026
66 days ago
CVE Severity & Scoring
Flow12 CVEs
25%
33%
42%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local5 (41.7%)
Network7 (58.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High3 (25.0%)
Unknown0 (0.0%)
User Interaction
None9 (75.0%)
Unknown0 (0.0%)
Required2 (16.7%)
Privileges Required
Low6 (50.0%)
High0 (0.0%)
None6 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31411HIGH Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (V | May 5, 2021 | 7.8 | 22 | NO | NO |
CVE-2021-31407HIGH Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to | Apr 23, 2021 | 7.5 | 22 | NO | NO |
CVE-2021-31405HIGH Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15 | Apr 23, 2021 | 7.5 | 22 | NO | NO |
CVE-2020-36321HIGH Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to | Apr 23, 2021 | 7.5 | 22 | NO | NO |
CVE-2020-36319MEDIUM Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application al | Apr 23, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-31408HIGH Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP metho | Apr 23, 2021 | 7.1 | 21 | NO | NO |
CVE-2019-25027MEDIUM Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaa | Apr 23, 2021 | 6.1 | 20 | NO | NO |
CVE-2021-31412MEDIUM Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14 (Vaadin 10.0.0 through 10.0.18), 1.1.0 prior to 2.0.0 (Vaad | Jun 24, 2021 | 5.3 | 18 | NO | NO |
A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever | May 19, 2026 | 1.6 | 16 | NO | NO |
CVE-2018-25007MEDIUM Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0.7, and 11.0.0 through 11.0.2) allows attacker to update ele | Apr 23, 2021 | 4.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Flow
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.0.0 | 1 | 2.5 | 0.2% | 0 | 0 |