com.vaadin:vaadin-server
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.vaadin:vaadin-serverpage 1 of 1
- CVE-2019-25028MEDIUMCVSS 5.4EG 5.4fixed in 7.7.20 or 8.8.5, by version range2021-04-23
vulnerable: 8.0.0 ... 8.8.4 (46 versions)
Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 through 7.7.19), and 8.0.0 through 8.8.4 (Vaadin 8.0.0 through 8.8.4) allows attacker to inject malicious JavaScript vi…
- CVE-2020-36320HIGHCVSS 7.5EG 7.5fixed in 7.7.222021-04-23
vulnerable: 7.0.0 ... 7.7.9 (136 versions)
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
- CVE-2021-31403MEDIUMCVSS 4.0EG 4.0fixed in 7.7.24 or 8.12.3, by version range2021-04-23
vulnerable: 8.0.0 ... 8.9.4 (66 versions)
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7.7.23 (Vaadin 7.0.0 through 7.7.23), and 8.0.0 through 8.12.2 (Vaadin 8.0.0 through 8.12.2) allows attacker to guess a …
- CVE-2021-33609MEDIUMCVSS 4.3EG 4.3fixed in 8.14.12021-10-13
vulnerable: 8.0.6 ... 8.9.4 (67 versions)
Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.
- CVE-2025-15022MEDIUMCVSS 4.8EG 4.8fixed in 7.7.50 or 8.30.0, by version range2026-01-05
vulnerable: 8.0.0 ... 8.9.4 (112 versions)
Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS) if caption content is derived from user input. In Vaadin Framework 7 and 8, the Action class is a general-purpose cla…
- CVE-2025-9467MEDIUMCVSS 5.3EG 5.3fixed in 7.7.48 or 8.28.2, by version range2025-09-04
vulnerable: 8.0.0 ... 8.9.4 (108 versions)
When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of affected versions should apply the following mitigation or upgrade. Releases that ha…
Check whether com.vaadin:vaadin-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.vaadin:vaadin-server CVEs against the assets you own.
Book a Demo →