VendorsProgresstelerik_ui_for_asp.net_ajaxall versions
Vulnerabilities

Progress Telerik UI For ASP.NET AJAX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2017-11357
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
Published 2017-08-23 · Analyzed
9.8KEV1 PoCEPSS 0.777
CVE-2019-19790
Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions were affected. To avoid this vulnerability, you must remove RadChart's HTTP handler from a web.config (its type is Telerik.Web.UI.ChartHttpHandler).
Published 2019-12-13 · Modified
9.8EPSS 0.030
CVE-2021-28141
An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web.UI.WebResource.axd file. This may allow the attacker to gain unauthorized access to the server and execute code. To exploit, one must use the parameter _TSM_HiddenField_ and inject a command at the end of the URI. NOTE: the vendor states that this is not a vulnerability. The request's output does not indicate that a "true" command was executed on the server, and the request's output does not leak any private source code or data from the server
Published 2021-03-11 · Modified
9.8EPSS 0.022
CVE-2026-6023
Deserialization of Untrusted Data Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-04-22 · Analyzed
9.8EPSS 0.007
CVE-2026-13186
AppDataStorageProvider Path Traversal Deserialization Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-07-22 · Analyzed
8.1EPSS 0.007
CVE-2026-13181
RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-07-22 · Analyzed
8.1EPSS 0.007
CVE-2026-13190
PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-07-22 · Analyzed
8.1EPSS 0.007
CVE-2026-13185
PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-07-22 · Analyzed
8.1EPSS 0.007
CVE-2026-13187
DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-07-22 · Analyzed
8.1EPSS 0.005
CVE-2025-3600
Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX
Published 2025-05-14 · Analyzed
7.5EPSS 0.241
CVE-2014-2217
Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata value.
Published 2014-12-25 · Modified
7.5EPSS 0.041
CVE-2026-13189
SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-07-22 · Analyzed
7.5EPSS 0.005
CVE-2026-6022
Uncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-04-22 · Analyzed
7.5EPSS 0.005
CVE-2026-13183
RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-07-22 · Analyzed
7.5EPSS 0.004
CVE-2026-13182
RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-07-22 · Analyzed
7.5EPSS 0.004
CVE-2026-13184
RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-07-22 · Analyzed
7.5EPSS 0.003
CVE-2026-13192
RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-07-22 · Analyzed
6.5EPSS 0.004
CVE-2026-14932
Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart
Published 2026-07-22 · Analyzed
6.5EPSS 0.004
CVE-2026-2878
Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-02-25 · Analyzed
5.9EPSS 0.003
CVE-2026-13188
DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX
Published 2026-07-22 · Analyzed
5.9EPSS 0.002
CVE-2026-14865
XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX
Published 2026-07-22 · Analyzed
5.3EPSS 0.004