Vulnerabilities > Svelte

DATE CVE VULNERABILITY TITLE RISK
2024-08-30 CVE-2024-45047 Cross-site Scripting vulnerability in Svelte
svelte performance oriented web framework.
network
low complexity
svelte CWE-79
6.1
2024-01-24 CVE-2024-23641 Unspecified vulnerability in Svelte Adapter-Node and KIT
SvelteKit is a web development kit.
network
low complexity
svelte
7.5
2023-04-06 CVE-2023-29008 Cross-Site Request Forgery (CSRF) vulnerability in Svelte Sveltekit 1.15.0/1.15.1
The SvelteKit framework offers developers an option to create simple REST APIs.
network
low complexity
svelte CWE-352
8.8
2023-04-04 CVE-2023-29003 Cross-Site Request Forgery (CSRF) vulnerability in Svelte Sveltekit 1.15.0
SvelteKit is a web development framework.
network
low complexity
svelte CWE-352
8.8
2022-07-12 CVE-2022-25875 Cross-site Scripting vulnerability in Svelte
The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering).
network
low complexity
svelte CWE-79
6.1
2021-04-05 CVE-2021-29261 Unspecified vulnerability in Svelte 104.6.4/104.7.0
The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.
local
low complexity
svelte
7.8