Csla
CSLA .NET provides a home for your business logic. It is an application development framework that reduces the cost of building and maintaining applications. The framework enables developers to build an object-oriented business layer for their application that encapsulates all business, authorization and validation logic for the application.
Activity
- Latest release
- 2d ago
- Total releases
- 21
- Cadence
- ~16 days
- Last 12 months
- 4
Details
- License
- MIT
- First release
- Oct 25, 2022
| Version | Released | |
|---|---|---|
10.2.0-beta.1
pre
|
10.2.0-beta.1
pre
Dependencies (21)
+ 13 more |
|
10.1.0
minor
|
10.1.0
minor
Dependencies (21)
+ 13 more |
|
10.0.0
major
|
10.0.0
major
Dependencies (21)
+ 13 more |
|
9.1.1
patch
|
9.1.1
patch
Dependencies (20)
+ 12 more |
|
9.1.0
minor
|
9.1.0
minor
Dependencies (20)
+ 12 more |
|
7.0.7
major
1 CVE
CVE-2024-28698
GHSA-9xhh-3m78-gvgj
Jul 22, 2024
CLSA Directory Traversal vulnerability
Critical
Network
Low
None
None
Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component. Fixes for this issue have been backported to the 5.x, 6.x, and 7.x branches of CSLA. CSLA version 5.5.4 contains a fix. As of time of publication, 6.x and 7.x do not have numbered versions containing the fix but do have fix commits available. Affected versions
5.0.0
5.0.0-R19052204
5.0.0-R19080501
5.0.0-R19082107
5.0.0-R19082803
5.0.0-R19090201
5.0.0-R19091001
5.0.0-R19091005
5.0.0-R19091601
5.0.0-R19091701
5.0.1
5.1.0
+ 61 more Show less
5.1.0-R19101002
5.1.0-R19110101
5.1.0-R19110701
5.1.0-R19122302
5.1.0-R20011901
5.1.0-R20012001
5.1.0-R20012201
5.1.0-R20020503
5.1.0-R20020701
5.2.0
5.2.0-R20040904
5.2.0-R20042401
5.2.0-R20042901
5.2.0-R20050802
5.3.0
5.3.0-R20062901
5.3.1
5.3.1-R20082601
5.3.2
5.4.0
5.4.0-R20111002
5.4.0-R20111202
5.4.0-R20113004
5.4.1
5.4.1-R21011901
5.4.2
5.4.2-R21040501
5.5.0
5.5.0-R21070101
5.5.0-R21071901
5.5.1
5.5.1-R21080301
5.5.1-R21082202
5.5.2
5.5.2-R21101501
5.5.3
6.0.0
6.1.0
6.1.0-R22070602
6.2.0
6.2.1
6.2.2
7.0.0
7.0.0-R23042102
7.0.0-R23042601
7.0.0-R23052201
7.0.1
7.0.2
7.0.3
7.0.3-R23113004
7.0.4
7.0.5
7.0.6
7.0.7
8.0.0-R23122103
8.0.0-R24010305
8.0.0-R24012202
8.0.0-R24021201
8.0.0-R24031201
8.0.0-R24031302
8.0.0-R24032503
Fixed in
5.5.4
8.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.0.7
major
Dependencies (18)
+ 10 more |
|
9.0.0
major
|
9.0.0
major
Dependencies (20)
+ 12 more |
|
8.2.9
patch
|
8.2.9
patch
Dependencies (18)
+ 10 more |
|
8.2.8
patch
|
8.2.8
patch
Dependencies (18)
+ 10 more |
|
8.2.7
patch
|
8.2.7
patch
Dependencies (18)
+ 10 more |
|
8.2.6
patch
|
8.2.6
patch
Dependencies (18)
+ 10 more |
|
5.5.4
initial
1 CVE
CVE-2025-66631
GHSA-wq34-7f4g-953v
Dec 08, 2025
Csla affected by Remote Code Execution via WcfProxy (NetDataContractSerializer)
High
Network
Low
None
None
ImpactVersions of CSLA .NET prior to version 6 allow the use of WcfProxy. WcfProxy uses the NetDataContractSerializer (NDCS) which has known vulnerabilities that can allow remote execution of code during deserialization. NDCS itself is considered obsolete, and you should avoid using WcfProxy or upgrade to CSLA 6 or higher where this issue does not exist. PatchesCSLA .NET version 6 and higher do not use WCF or NetDataContractSerializer. WorkaroundsIf you are using a version CSLA .NET older than version 6, you should stop using WcfProxy in your data portal configuration. Doing this avoids the use of WCF and the NetDataContractSerializer, avoiding the vulnerability. Affected versions
5.0.0
5.0.0-R19052204
5.0.0-R19080501
5.0.0-R19082107
5.0.0-R19082803
5.0.0-R19090201
5.0.0-R19091001
5.0.0-R19091005
5.0.0-R19091601
5.0.0-R19091701
5.0.1
5.1.0
+ 42 more Show less
5.1.0-R19101002
5.1.0-R19110101
5.1.0-R19110701
5.1.0-R19122302
5.1.0-R20011901
5.1.0-R20012001
5.1.0-R20012201
5.1.0-R20020503
5.1.0-R20020701
5.2.0
5.2.0-R20040904
5.2.0-R20042401
5.2.0-R20042901
5.2.0-R20050802
5.3.0
5.3.0-R20062901
5.3.1
5.3.1-R20082601
5.3.2
5.4.0
5.4.0-R20111002
5.4.0-R20111202
5.4.0-R20113004
5.4.1
5.4.1-R21011901
5.4.2
5.4.2-R21040501
5.5.0
5.5.0-R21070101
5.5.0-R21071901
5.5.1
5.5.1-R21080301
5.5.1-R21082202
5.5.2
5.5.2-R21101501
5.5.3
5.5.4
6.0.0-R22020902
6.0.0-R22022201
6.0.0-R22031601
6.0.0-R22040701
6.0.0-R22042501
Fixed in
6.0.0
References
Updated Dec 09, 2025 · Source: OSV.dev |
5.5.4
initial
Dependencies (17)
+ 9 more |
|
8.2.5
patch
|
8.2.5
patch
Dependencies (18)
+ 10 more |
|
8.2.4
patch
|
8.2.4
patch
Dependencies (18)
+ 10 more |
|
8.2.3
patch
|
8.2.3
patch
Dependencies (18)
+ 10 more |
|
8.2.2
patch
|
8.2.2
patch
Dependencies (18)
+ 10 more |
|
8.2.1
patch
|
8.2.1
patch
Dependencies (18)
+ 10 more |
|
8.2.0
minor
|
8.2.0
minor
Dependencies (18)
+ 10 more |
|
8.1.1
patch
|
8.1.1
patch
Dependencies (18)
+ 10 more |
|
8.1.0
major
|
8.1.0
major
Dependencies (18)
+ 10 more |
|
6.2.2
major
1 CVE
CVE-2024-28698
GHSA-9xhh-3m78-gvgj
Jul 22, 2024
CLSA Directory Traversal vulnerability
Critical
Network
Low
None
None
Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component. Fixes for this issue have been backported to the 5.x, 6.x, and 7.x branches of CSLA. CSLA version 5.5.4 contains a fix. As of time of publication, 6.x and 7.x do not have numbered versions containing the fix but do have fix commits available. Affected versions
5.0.0
5.0.0-R19052204
5.0.0-R19080501
5.0.0-R19082107
5.0.0-R19082803
5.0.0-R19090201
5.0.0-R19091001
5.0.0-R19091005
5.0.0-R19091601
5.0.0-R19091701
5.0.1
5.1.0
+ 61 more Show less
5.1.0-R19101002
5.1.0-R19110101
5.1.0-R19110701
5.1.0-R19122302
5.1.0-R20011901
5.1.0-R20012001
5.1.0-R20012201
5.1.0-R20020503
5.1.0-R20020701
5.2.0
5.2.0-R20040904
5.2.0-R20042401
5.2.0-R20042901
5.2.0-R20050802
5.3.0
5.3.0-R20062901
5.3.1
5.3.1-R20082601
5.3.2
5.4.0
5.4.0-R20111002
5.4.0-R20111202
5.4.0-R20113004
5.4.1
5.4.1-R21011901
5.4.2
5.4.2-R21040501
5.5.0
5.5.0-R21070101
5.5.0-R21071901
5.5.1
5.5.1-R21080301
5.5.1-R21082202
5.5.2
5.5.2-R21101501
5.5.3
6.0.0
6.1.0
6.1.0-R22070602
6.2.0
6.2.1
6.2.2
7.0.0
7.0.0-R23042102
7.0.0-R23042601
7.0.0-R23052201
7.0.1
7.0.2
7.0.3
7.0.3-R23113004
7.0.4
7.0.5
7.0.6
7.0.7
8.0.0-R23122103
8.0.0-R24010305
8.0.0-R24012202
8.0.0-R24021201
8.0.0-R24031201
8.0.0-R24031302
8.0.0-R24032503
Fixed in
5.5.4
8.0.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.2.2
major
Dependencies (16)
+ 8 more |