LIVE · cybersecurity feed
Live wire
vendor

Svelte

6 CVEs published in the last four months. Exploited flaws first.

Critical0
High6
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-302267.5highdevalueSvelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient fo213d ago
CVE-2026-425677.5highsvelteSvelte is a performance oriented web framework.123d ago
CVE-2026-425707.5highdevalueSvelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient fo123d ago
CVE-2026-822597.5highsveltekitSvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the e43d ago
CVE-2026-822607.5highsveltekitSvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFu43d ago
CVE-2026-822617.5highsveltekitSvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled conta43d ago

Filter the full tracker by Svelte →