Known Vulnerabilities for Designer by Vaadin
Listed below are 1 of the newest known vulnerabilities associated with "Designer" by "Vaadin".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-36765 json | An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated at... | Not Provided | 2026-04-30 | 2026-05-04 |
| CVE-2026-34684 json | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in ... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-34683 json | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in ... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-34682 json | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in ... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-34681 json | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in ... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-34664 json | Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Direc... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-27096 json | Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme colorfolio al... | Not Provided | 2026-03-19 | 2026-04-23 |
| CVE-2026-25371 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Produ... | Not Provided | 2026-03-25 | 2026-04-24 |
| CVE-2026-21994 json | Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projec... | Not Provided | 2026-03-17 | 2026-03-18 |
| CVE-2026-21340 json | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to mem... | Not Provided | 2026-02-10 | 2026-04-28 |