📦 Svelte

by Svelte

🔍 What is Svelte?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-29261

HIGH CVSS 7.8 Apr 5, 2021

This vulnerability in the unofficial Svelte extension for Visual Studio Code allows attackers to execute arbitrary code by tricking users into opening a malicious workspace configuration. It affects d...

CVE-2026-27901

MEDIUM CVSS 6.1 Feb 26, 2026

This vulnerability in Svelte web framework allows HTML injection and Cross-Site Scripting (XSS) when using bind:innerText or bind:textContent on contenteditable elements with untrusted data. It affect...

CVE-2026-27121

MEDIUM CVSS 5.4 Feb 20, 2026

Svelte versions before 5.51.5 are vulnerable to cross-site scripting (XSS) during server-side rendering when using spread syntax with untrusted data. This allows attackers to inject malicious event ha...

CVE-2026-27125

MEDIUM CVSS 6.8 Feb 20, 2026

This vulnerability in Svelte's server-side rendering allows attribute spreading on elements to enumerate inherited properties from an object's prototype chain when Object.prototype pollution exists. T...

CVE-2025-15265

MEDIUM CVSS 6.1 Jan 15, 2026

This vulnerability allows attackers to execute arbitrary JavaScript in users' browsers by injecting malicious keys into Svelte's async hydration process. When exploited, it enables cross-site scriptin...

CVE-2024-45047

MEDIUM CVSS 5.4 Aug 30, 2024

This CVE describes a mutation XSS (mXSS) vulnerability in Svelte's server-side rendering where HTML escaping is improperly handled. Attackers can inject malicious content into attributes within noscri...