Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Telerik UI for ASP.NET AJAX — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in Telerik UI for ASP.NET AJAX, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities associated with the Telerik UI for ASP.NET AJAX product, categorized under standard weakness types and indexed with relevant security tags. It aggregates a comprehensive collection of security flaws, ranging from cross-site scripting and path traversal to privilege escalation issues, covering disclosed incidents from early 2010 through to the most recent updates in 2024. By centralizing these records, the resource allows security professionals and developers to track vendor advisories efficiently, understand the specific characteristics of each weakness class as it applies to this framework, and examine the complete vulnerability history of the product to assess long-term risk profiles. The entries include detailed descriptions of the affected versions, the nature of the exploits, and the status of mitigation efforts, providing a clear roadmap for remediation. This structured approach facilitates a deeper analysis of how legacy components interact with modern web application architectures and highlights common patterns in coding errors that lead to security breaches. Users can leverage this data to prioritize patching strategies, conduct impact assessments, and ensure compliance with internal security standards by referencing verified historical data rather than relying on fragmented news sources or isolated reports.

Vendor: Progress Software

CVE IDTitleCVSSSeverityPublished
CVE-2026-14932 Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart CWE-321 6.5 Medium2026-07-22
CVE-2026-14865 XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX CWE-776 5.3 Medium2026-07-22
CVE-2026-13192 RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX CWE-918 6.5 Medium2026-07-22
CVE-2026-13190 PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX CWE-502 8.1 High2026-07-22
CVE-2026-13189 SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX CWE-36 7.5 High2026-07-22
CVE-2026-13188 DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX CWE-345 5.9 Medium2026-07-22
CVE-2026-13187 DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAX CWE-470 8.1 High2026-07-22
CVE-2026-13186 AppDataStorageProvider Path Traversal Deserialization Vulnerability in Telerik UI for ASP.NET AJAX CWE-22 8.1 High2026-07-22
CVE-2026-13185 PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAX CWE-502 8.1 High2026-07-22
CVE-2026-13184 RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX CWE-321 7.5 High2026-07-22
CVE-2026-13183 RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX CWE-208 7.5 High2026-07-22
CVE-2026-13182 RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX CWE-209 7.5 High2026-07-22
CVE-2026-13181 RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX CWE-470 8.1 High2026-07-22
CVE-2026-6023 Deserialization of Untrusted Data Vulnerability in Telerik UI for ASP.NET AJAX CWE-502 8.1 High2026-04-22
CVE-2026-6022 Uncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAX CWE-400 7.5 High2026-04-22
CVE-2026-2878 Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAX CWE-331 5.3 Medium2026-02-25
CVE-2025-3600 Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX 7.5 High2025-05-14

All 17 known CVE vulnerabilities affecting Telerik UI for ASP.NET AJAX with full Chinese analysis, references, and POCs where available.