Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.60% | — | Svelte KIT | 15/1/2026 | 17/6/2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote function uses a binary data format containing a representation of submitted form data. A specially-crafted payload can cause the server to allocate a large amount of… | |
| Modificada | Alta (7.5) | 0.64% | — | Svelte Devalue | 15/1/2026 | 15/7/2026 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.1.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input from untrusted… | |
| Modificada | Alta (7.5) | 0.64% | — | Svelte Devalue | 15/1/2026 | 15/7/2026 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input from untrusted… | |
| Analizada | Alta (8.4) | 0.53% | — | Svelte Adapter-nodeSvelte KIT | 15/1/2026 | 17/6/2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a server side request forgery (SSRF) and denial of service (DoS) under certain conditions. From 2.44.0 through 2.49.4, the vulnerability results in a DoS when your app has at… | |
| Aplazada | Alta (8.3) | 0.55% | — | Sveltekit-superformsAI | 15/10/2025 | 17/6/2026 | sveltekit-superforms makes SvelteKit forms a pleasure to use. sveltekit-superforms v2.27.3 and prior are susceptible to a prototype pollution vulnerability within the parseFormData function of formData.js. An attacker can inject string and array properties into Object.prototype, leading to denial of service, type… | |
| Aplazada | Alta (7.9) | 0.37% | — | Svelte DevalueAI | 26/8/2025 | 17/6/2026 | Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object with a __proto__ property and devalue.parse does not check that an index is numeric. This could result in assigning prototypes to objects and properties, leading to prototype pollution. This issue… | |
| Aplazada | Media (5.4) | 0.30% | — | SveltekitAI | 15/4/2025 | 17/6/2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.20.6 , unsanitized search param names cause XSS vulnerability. You are affected if you iterate over all entries of event.url.searchParams inside a server load function. Attackers can exploit it by crafting a… | |
| Analizada | Baja (2) | 0.48% | — | Sveltekit | 25/11/2024 | 17/6/2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html template for errors contains placeholders that are replaced without escaping the content first. error.html is the page that is rendered when everything else fails. It can contain the following… | |
| Analizada | Baja (2) | 0.33% | — | Sveltekit | 25/11/2024 | 17/6/2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input from *the request URL* flows into `end`, where it is used to render an HTML page returned to the user. This may result in a Cross-Site Scripting attack (XSS)." The files… | |
| Analizada | Media (6.1) | 0.36% | — | Svelte | 30/8/2024 | 17/6/2026 | svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not including 4.2.19. Svelte improperly escapes HTML on server-side rendering. The assumption is that attributes will always stay as such, but in some situation the final DOM tree rendered on browsers is… | |
| Aplazada | Media (6.5) | 0.29% | — | CmsaassstarterAITailwindAISupabaseAISveltekitAI | 14/5/2024 | 17/6/2026 | CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarter template before commit 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 are impacted. The issue is the user JWT Token is not verified on server session. You should take the patch… | |
| Modificada | Alta (7.5) | 0.76% | — | Svelte Adapter-nodeSvelte KIT | 24/1/2024 | 17/6/2026 | SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/hosted sveltekit app throws `Request with GET/HEAD method cannot have body.` and crashes the preview/hosting. After this happens, one must manually restart the app. `TRACE` requests will also cause… | |
| Modificada | Alta (8.8) | 0.37% | — | Sveltekit | 6/4/2023 | 17/6/2026 | The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request forgery (CSRF) protection to its users. The protection is implemented at… | |
| Modificada | Alta (8.8) | 0.56% | — | Sveltekit | 4/4/2023 | 17/6/2026 | SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request forgery (CSRF) protection to its users.… | |
| Modificada | Media (6.1) | 1.4% | — | Svelte | 12/7/2022 | 17/6/2026 | The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function. | |
| Modificada | Alta (7.8) | 1.2% | — | Svelte | 5/4/2021 | 17/6/2026 | The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration. |