VulnSea

dotvvm vulnerabilities

CVEs whose affected-version data names the dotvvm package (nuget). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-57581Medium· 5.3
1w ago

DotVVM is an open source MVVM framework for web applications

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMi…

Sunlitriganti · dotvvmEPSS 0.44%via NVD
CVE-2026-57578Critical· 9.2
1w ago

DotVVM is an open source MVVM framework for web applications

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explicit ICommandActionFilter.OnCommandExecutingAsync, IViewMod…

Midnightriganti · dotvvmEPSS 0.44%via NVD
CVE-2026-57577High· 8.2
1w ago

DotVVM is an open source MVVM framework for web applications

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path segment can cause excessive regular-expression backtrackin…

Twilightriganti · dotvvmEPSS 0.43%via NVD
GHSA-c2g3-c4gc-w5wgHigh
3mo ago

ReDoS in DotVVM routing

ReDoS in DotVVM routing

TwilightDotVVM · DotVVMvia GHSA
GHSA-c8qj-jx8j-fg2wCritical
3mo ago

DotVVM: Missing authorization in AuthorizeActionFilter

DotVVM: Missing authorization in AuthorizeActionFilter

MidnightDotVVM · DotVVMvia GHSA
GHSA-2rm3-333w-xvc4Medium· 5.3
3mo ago

DotVVM: Unrestricted file upload

DotVVM: Unrestricted file upload

SunlitDotVVM · DotVVMvia GHSA
dotvvm vulnerabilities (CVEs) · VulnSea