Vulnerabilities

Summary — last 7 days

New vulnerabilities2,703▼ 615 vs. last week
Critical / high1,293▼ 208 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)291▼ 219 vs. last week
–

11 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisMedium (4.1)0.13%—Quasar APP ViteAI10/6/202610/6/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. From 1.0.0 until 3.3.0, @quasar/app-vite recursively removed the resolved build.distDir before building without rejecting the project root, user home directory, filesystem roots, or symlink-resolved external directories. An unsafe…
Awaiting AnalysisHigh (8.3)0.27%—Quasar FrameworkAI10/6/202610/6/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 3.3.0, several @quasar/app-vite SSR and SSG rendering paths interpolated ssrContext.nonce directly into quoted HTML attributes. An application that derives or overrides this value with attacker-controlled data can allow a…
Awaiting AnalysisHigh (7.1)0.28%—Quasar Render SSR ErrorAIQuasar APP ViteAI10/6/202610/6/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/render-ssr-error 2.2.4 and @quasar/app-vite 3.3.0, renderSSRError() in utils/render-ssr-error/src/index.js used diagnostic data from utils/render-ssr-error/src/env.js to serialize process.env, request headers, and…
Awaiting AnalysisHigh (8.4)0.07%—Quasar SSL CertificateAIQuasar CLIAIQuasar APP ViteAI10/6/202610/6/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0, the @quasar/ssl-certificate utility cached a combined private key and certificate PEM without explicitly applying owner-only filesystem…
Awaiting AnalysisHigh (8.7)0.29%—QuasarAI10/6/202610/6/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.23.3, Platform.parseSSR() passed an unbounded User-Agent request header to getMatch() in ui/src/plugins/platform/Platform.js, whose browser-detection expressions combined greedy captures with repeated unbounded scans.…
Awaiting AnalysisHigh (7.1)0.29%—Quasar IcongenieAI10/6/202610/6/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory.…
Awaiting AnalysisCritical (10)0.30%—QuasarAI10/6/202610/6/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute…
Awaiting AnalysisLow (3.1)0.26%—QuasarAI10/6/202610/6/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.32.2, the openURL() utility in ui/src/utils/open-url/open-url.js trusted window.SafariViewController whenever that global existed in an iOS environment. Attacker-controlled HTML rendered by components such as QEditor can…
DeferredMedium (5.6)0.39%—Quasar FrameworkAI8/13/20269/9/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without rejecting an own __proto__ property. The merge…
AnalyzedMedium (6.1)0.21%—Quasar Qmarkdown4/20/20256/17/2026
QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.
ModifiedHigh (8.8)0.69%—Quasar-form Quasar Form11/4/20236/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nucleus_genius Quasar form free – Contact Form Builder for WordPress allows SQL Injection.This issue affects Quasar form free – Contact Form Builder for WordPress: from n/a through 6.0.