Known Vulnerabilities for Vaadin by Vendor
Listed below are 7 of the newest known vulnerabilities associated with "Vaadin" by "Vendor".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-93547 json | A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-91860 json | A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an o... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-7860 json | A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the f... | Not Provided | 2026-05-19 | 2026-09-14 |
| CVE-2025-9467 json | When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the u... | Not Provided | 2025-09-04 | 2026-09-14 |
| CVE-2023-25500 json | Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 ... | Not Provided | 2023-06-22 | 2026-09-14 |
| CVE-2023-25499 json | When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22,... | Not Provided | 2023-06-22 | 2026-09-14 |
| CVE-2022-29567 json | The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication ... | Not Provided | 2022-05-24 | 2026-09-14 |