Vulnerabilities > Svelte
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-08-30 | CVE-2024-45047 | Cross-site Scripting vulnerability in Svelte svelte performance oriented web framework. | 6.1 |
2024-01-24 | CVE-2024-23641 | Unspecified vulnerability in Svelte Adapter-Node and KIT SvelteKit is a web development kit. | 7.5 |
2023-04-06 | CVE-2023-29008 | Cross-Site Request Forgery (CSRF) vulnerability in Svelte Sveltekit 1.15.0/1.15.1 The SvelteKit framework offers developers an option to create simple REST APIs. | 8.8 |
2023-04-04 | CVE-2023-29003 | Cross-Site Request Forgery (CSRF) vulnerability in Svelte Sveltekit 1.15.0 SvelteKit is a web development framework. | 8.8 |
2022-07-12 | CVE-2022-25875 | Cross-site Scripting vulnerability in Svelte The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). | 6.1 |
2021-04-05 | CVE-2021-29261 | Unspecified vulnerability in Svelte 104.6.4/104.7.0 The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration. | 7.8 |