Qwik
by Qwik
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-1283 | Cri | 0.58 | 10.0 | 0.01 | Mar 8, 2023 | Code Injection in GitHub repository builderio/qwik prior to 0.21.0. | ||
| CVE-2026-27971 | Cri | 0.57 | 9.8 | 0.05 | Mar 3, 2026 | Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any… | ||
| CVE-2026-25150 | Cri | 0.53 | 9.3 | 0.01 | Feb 3, 2026 | Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form field names with dot notation (e.g., user.name) to create… | ||
| CVE-2026-32701 | Hig | 0.42 | 7.5 | 0.00 | Mar 20, 2026 | Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form field names during FormData parsing. By submitting mixed array-index and object-property keys for the same path, an attacker could cause user-controlled… | ||
| CVE-2024-41677 | Med | 0.34 | 6.3 | 0.01 | Aug 6, 2024 | Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions up to but not including 1.6.0. Qwik improperly escapes HTML on server-side rendering. It converts strings according to the rules found in the `render-ssr.ts`… | ||
| CVE-2026-25149 | Med | 0.33 | 6.1 | 0.00 | Feb 3, 2026 | Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler middleware allows a remote attacker to redirect users to arbitrary protocol-relative URLs. Successful exploitation permits attackers… | ||
| CVE-2026-25148 | Med | 0.33 | 6.1 | 0.00 | Feb 3, 2026 | Qwik is a performance focused javascript framework. Prior to version 1.19.0, a Cross-Site Scripting vulnerability in Qwik.js' server-side rendering virtual attribute serialization allows a remote attacker to inject arbitrary web scripts into server-rendered pages via virtual… | ||
| CVE-2023-0410 | Med | 0.33 | 6.1 | 0.00 | Jan 20, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5. | ||
| CVE-2026-25155 | Med | 0.31 | 5.9 | 0.00 | Feb 3, 2026 | Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers. This issue has been patched in version 1.12.0. | ||
| CVE-2026-25151 | Med | 0.31 | 5.9 | 0.00 | Feb 3, 2026 | Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inconsistently interprets HTTP request headers, which can be abused by a remote attacker to circumvent form submission CSRF protections using specially crafted… | ||
| CVE-2023-2307 | Med | 0.24 | 4.7 | 0.00 | Apr 26, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0. |
- risk 0.58cvss 10.0epss 0.01
Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
- risk 0.57cvss 9.8epss 0.05
Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any…
- risk 0.53cvss 9.3epss 0.01
Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form field names with dot notation (e.g., user.name) to create…
- risk 0.42cvss 7.5epss 0.00
Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form field names during FormData parsing. By submitting mixed array-index and object-property keys for the same path, an attacker could cause user-controlled…
- risk 0.34cvss 6.3epss 0.01
Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions up to but not including 1.6.0. Qwik improperly escapes HTML on server-side rendering. It converts strings according to the rules found in the `render-ssr.ts`…
- risk 0.33cvss 6.1epss 0.00
Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler middleware allows a remote attacker to redirect users to arbitrary protocol-relative URLs. Successful exploitation permits attackers…
- risk 0.33cvss 6.1epss 0.00
Qwik is a performance focused javascript framework. Prior to version 1.19.0, a Cross-Site Scripting vulnerability in Qwik.js' server-side rendering virtual attribute serialization allows a remote attacker to inject arbitrary web scripts into server-rendered pages via virtual…
- risk 0.33cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5.
- risk 0.31cvss 5.9epss 0.00
Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers. This issue has been patched in version 1.12.0.
- risk 0.31cvss 5.9epss 0.00
Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inconsistently interprets HTTP request headers, which can be abused by a remote attacker to circumvent form submission CSRF protections using specially crafted…
- risk 0.24cvss 4.7epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.