Vulnerabilities
Summary — last 7 days
New vulnerabilities2,703▼ 615 vs. last week
Critical / high1,293▼ 208 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)291▼ 219 vs. last week
11 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (4.1) | 0.13% | — | Quasar APP ViteAI | 10/6/2026 | 10/6/2026 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. From 1.0.0 until 3.3.0, @quasar/app-vite recursively removed the resolved build.distDir before building without rejecting the project root, user home directory, filesystem roots, or symlink-resolved external directories. An unsafe… | |
| Awaiting Analysis | High (8.3) | 0.27% | — | Quasar FrameworkAI | 10/6/2026 | 10/6/2026 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 3.3.0, several @quasar/app-vite SSR and SSG rendering paths interpolated ssrContext.nonce directly into quoted HTML attributes. An application that derives or overrides this value with attacker-controlled data can allow a… | |
| Awaiting Analysis | High (7.1) | 0.28% | — | Quasar Render SSR ErrorAIQuasar APP ViteAI | 10/6/2026 | 10/6/2026 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/render-ssr-error 2.2.4 and @quasar/app-vite 3.3.0, renderSSRError() in utils/render-ssr-error/src/index.js used diagnostic data from utils/render-ssr-error/src/env.js to serialize process.env, request headers, and… | |
| Awaiting Analysis | High (8.4) | 0.07% | — | Quasar SSL CertificateAIQuasar CLIAIQuasar APP ViteAI | 10/6/2026 | 10/6/2026 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0, the @quasar/ssl-certificate utility cached a combined private key and certificate PEM without explicitly applying owner-only filesystem… | |
| Awaiting Analysis | High (8.7) | 0.29% | — | QuasarAI | 10/6/2026 | 10/6/2026 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.23.3, Platform.parseSSR() passed an unbounded User-Agent request header to getMatch() in ui/src/plugins/platform/Platform.js, whose browser-detection expressions combined greedy captures with repeated unbounded scans.… | |
| Awaiting Analysis | High (7.1) | 0.29% | — | Quasar IcongenieAI | 10/6/2026 | 10/6/2026 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory.… | |
| Awaiting Analysis | Critical (10) | 0.30% | — | QuasarAI | 10/6/2026 | 10/6/2026 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute… | |
| Awaiting Analysis | Low (3.1) | 0.26% | — | QuasarAI | 10/6/2026 | 10/6/2026 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.32.2, the openURL() utility in ui/src/utils/open-url/open-url.js trusted window.SafariViewController whenever that global existed in an iOS environment. Attacker-controlled HTML rendered by components such as QEditor can… | |
| Deferred | Medium (5.6) | 0.39% | — | Quasar FrameworkAI | 8/13/2026 | 9/9/2026 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without rejecting an own __proto__ property. The merge… | |
| Analyzed | Medium (6.1) | 0.21% | — | Quasar Qmarkdown | 4/20/2025 | 6/17/2026 | QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set. | |
| Modified | High (8.8) | 0.69% | — | Quasar-form Quasar Form | 11/4/2023 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nucleus_genius Quasar form free – Contact Form Builder for WordPress allows SQL Injection.This issue affects Quasar form free – Contact Form Builder for WordPress: from n/a through 6.0. |