dotvvm vulnerabilities
CVEs whose affected-version data names the dotvvm package (nuget). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2026-57581Medium· 5.3DotVVM is an open source MVVM framework for web applications
DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMi…
CVE-2026-57578Critical· 9.2DotVVM is an open source MVVM framework for web applications
DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explicit ICommandActionFilter.OnCommandExecutingAsync, IViewMod…
CVE-2026-57577High· 8.2DotVVM is an open source MVVM framework for web applications
DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path segment can cause excessive regular-expression backtrackin…
GHSA-c2g3-c4gc-w5wgHighReDoS in DotVVM routing
ReDoS in DotVVM routing
GHSA-c8qj-jx8j-fg2wCriticalDotVVM: Missing authorization in AuthorizeActionFilter
DotVVM: Missing authorization in AuthorizeActionFilter
GHSA-2rm3-333w-xvc4Medium· 5.3DotVVM: Unrestricted file upload
DotVVM: Unrestricted file upload