<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Svelte</title>
  <link>https://cvedaily.com/pages/tags/svelte.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/svelte.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Svelte</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:41 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-48149 – Budibase is an open-source low-code platform. Prior to 3.39.0, the Budibase Text...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48149</guid>
    <pubDate>Wed, 27 May 2026 18:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48149</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.39.0, the Budibase Text component renders markdown by assigning marked.parse(markdown) straight to innerHTML with no sanitizer (packages/bbui/src/Markdown/MarkdownViewer.svelte:22). Any column a builder binds to a Text component in Markdown mode is a stored-XSS sink writable by every BASIC app user with WRITE on the underlying table. This v…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44568 – Open WebUI is a self-hosted artificial intelligence platform designed to operate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44568</guid>
    <pubDate>Fri, 15 May 2026 20:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44568</strong></p>
  <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the AccountPending.svelte component renders the admin-configured "Pending User Overlay Content" using marked.parse() inside {@html} with an incorrect DOMPurify application order. An admin can inject arbitrary JavaScript into the Pending User Overlay Content that executes in the brows…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-6216 – A security vulnerability has been detected in DbGate up to 7.1.4. This affects a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6216</guid>
    <pubDate>Mon, 13 Apr 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-6216</strong></p>
  <p>A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 7.1.5 mitig…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40074 – SvelteKit is a framework for rapidly developing robust, performant web applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40074</guid>
    <pubDate>Fri, 10 Apr 2026 17:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40074</strong></p>
  <p>SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, redirect, when called from inside the handle server hook with a location parameter containing characters that are invalid in a HTTP header, will cause an unhandled TypeError. This could result in DoS on some platforms, especially if the location passed to redirect contains unsanitize…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40073 – SvelteKit is a framework for rapidly developing robust, performant web applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40073</guid>
    <pubDate>Fri, 10 Apr 2026 17:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40073</strong></p>
  <p>SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under certain circumstances, requests could bypass the BODY_SIZE_LIMIT on SvelteKit applications running with adapter-node. This bypass does not affect body size limits at other layers of the application stack, so limits enforced in the WAF, gateway, or at the platform level are unaf…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35218 – Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase'...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35218</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35218</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity names (tables, views, queries, automations) using Svelte's {@html} directive without any sanitization. An authenticated user with Builder access can create a table, automation, view, or query whose name contains an HTML payload (e.g. <img src=x onerror=alert(document.domain)>).…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30226 – Svelte devalue is a JavaScript library that serializes values into strings when ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30226</guid>
    <pubDate>Wed, 11 Mar 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30226</strong></p>
  <p>Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In devalue v5.6.3 and earlier, devalue.parse and devalue.unflatten were susceptible to prototype pollution via maliciously crafted payloads. Successful exploitation could lead to Denial of Service (DoS) or type confusion. This vulnerability is fixed in 5.6.4.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27902 – Svelte performance oriented web framework. Prior to version 5.53.5, errors from ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27902</guid>
    <pubDate>Thu, 26 Feb 2026 02:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27902</strong></p>
  <p>Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from `transformError`. Version 5.53.5 fixes the issue.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27901 – Svelte performance oriented web framework. Prior to version 5.53.5, the contents...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27901</guid>
    <pubDate>Thu, 26 Feb 2026 02:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27901</strong></p>
  <p>Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textContent` on `contenteditable` elements were not properly escaped. This could enable HTML injection and Cross-Site Scripting (XSS) if rendering untrusted data as the binding's initial value on the server. Version 5.53.5 fixes the issue.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27125 – svelte performance oriented web framework. Prior to 5.51.5, in server-side rende...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27125</guid>
    <pubDate>Fri, 20 Feb 2026 23:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27125</strong></p>
  <p>svelte performance oriented web framework. Prior to 5.51.5, in server-side rendering, attribute spreading on elements (e.g. <div {...attrs}>) enumerates inherited properties from the object's prototype chain rather than only own properties. In environments where Object.prototype has already been polluted — a precondition outside of Svelte's control — this can cause unexpected attributes to appear…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27122 – svelte performance oriented web framework. Prior to 5.51.5, when using &lt;svelte:e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27122</guid>
    <pubDate>Fri, 20 Feb 2026 23:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27122</strong></p>
  <p>svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27121 – svelte performance oriented web framework. Versions of svelte prior to 5.51.5 ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27121</guid>
    <pubDate>Fri, 20 Feb 2026 23:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27121</strong></p>
  <p>svelte performance oriented web framework. Versions of svelte prior to 5.51.5 are vulnerable to cross-site scripting (XSS) during server-side rendering. When using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicio…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27119 – svelte performance oriented web framework. From 5.39.3, &lt;=5.51.4, in certain cir...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27119</guid>
    <pubDate>Fri, 20 Feb 2026 23:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27119</strong></p>
  <p>svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering output of an <option> element does not properly escape its content, potentially allowing HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27118 – SvelteKit is a framework for rapidly developing robust, performant web applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27118</guid>
    <pubDate>Fri, 20 Feb 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27118</strong></p>
  <p>SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Versions of @sveltejs/adapter-vercel prior to 6.3.2 are vulnerable to cache poisoning. An internal query parameter intended for Incremental Static Regeneration (ISR) is accessible on all routes, allowing an attacker to cause sensitive user-specific responses to be cached and served to other users. Su…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-15265 – An SSR XSS exists in async hydration when attacker‑controlled keys are passed to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15265</guid>
    <pubDate>Thu, 15 Jan 2026 20:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-15265</strong></p>
  <p>An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside a <script> block without HTML‑safe escaping, allowing </script> to terminate the script and inject arbitrary JavaScript. This enables remote script execution in users' browsers, with potential for session theft and account compromise. This issue affects Svelte: from 5.46.0 befor…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22803 – SvelteKit is a framework for rapidly developing robust, performant web applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22803</guid>
    <pubDate>Thu, 15 Jan 2026 19:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22803</strong></p>
  <p>SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote function uses a binary data format containing a representation of submitted form data. A specially-crafted payload can cause the server to allocate a large amount of memory, causing DoS via memory exhaustion. This vulnerability is fixed in 2.49.5.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22775 – Svelte devalue is a JavaScript library that serializes values into strings when ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22775</guid>
    <pubDate>Thu, 15 Jan 2026 19:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22775</strong></p>
  <p>Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.1.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input from untrusted sources. This affects applications using devalue.parse on externally-supplied data. T…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-405</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22774 – Svelte devalue is a JavaScript library that serializes values into strings when ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22774</guid>
    <pubDate>Thu, 15 Jan 2026 19:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22774</strong></p>
  <p>Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input from untrusted sources. This affects applications using devalue.parse on externally-supplied data. T…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-405</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67647 – SvelteKit is a framework for rapidly developing robust, performant web applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67647</guid>
    <pubDate>Thu, 15 Jan 2026 19:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67647</strong></p>
  <p>SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a server side request forgery (SSRF) and denial of service (DoS) under certain conditions. From 2.44.0 through 2.49.4, the vulnerability results in a DoS when your app has at least one prerendered route (export const prerender = true). From 2.19.0 through 2…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57820 – Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57820</guid>
    <pubDate>Tue, 26 Aug 2025 23:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57820</strong></p>
  <p>Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object with a __proto__ property and devalue.parse does not check that an index is numeric. This could result in assigning prototypes to objects and properties, leading to prototype pollution. This issue has been fixed in version 5.3.2</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-32388 – SvelteKit is a framework for rapidly developing robust, performant web applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32388</guid>
    <pubDate>Tue, 15 Apr 2025 23:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-32388</strong></p>
  <p>SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.20.6 , unsanitized search param names cause XSS vulnerability. You are affected if you iterate over all entries of event.url.searchParams inside a server load function. Attackers can exploit it by crafting a malicious URL and getting a user to click a link with said URL. This vulnerability…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-26260 – Plenti &lt;= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' file...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26260</guid>
    <pubDate>Wed, 12 Mar 2025 16:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-26260</strong></p>
  <p>Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-53262 – SvelteKit is a framework for rapidly developing robust, performant web applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53262</guid>
    <pubDate>Mon, 25 Nov 2024 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-53262</strong></p>
  <p>SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html template for errors contains placeholders that are replaced without escaping the content first. error.html is the page that is rendered when everything else fails. It can contain the following placeholders: %sveltekit.status% — the HTTP status, and %sveltekit.error.message% — th…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-53261 – SvelteKit is a framework for rapidly developing robust, performant web applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53261</guid>
    <pubDate>Mon, 25 Nov 2024 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-53261</strong></p>
  <p>SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input from *the request URL* flows into `end`, where it is used to render an HTML page returned to the user. This may result in a Cross-Site Scripting attack (XSS)." The files `packages/kit/src/exports/vite/dev/index.js` and `packages/kit/src/exports/vite/utils.js` both contain user cont…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45047 – svelte performance oriented web framework. A potential mXSS vulnerability exists...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45047</guid>
    <pubDate>Fri, 30 Aug 2024 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45047</strong></p>
  <p>svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not including 4.2.19. Svelte improperly escapes HTML on server-side rendering. The assumption is that attributes will always stay as such, but in some situation the final DOM tree rendered on browsers is different from what Svelte expects on server-side rendering. This may be leverage…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-38687 – Svelecte is a flexible autocomplete/select component written in Svelte. Svelecte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38687</guid>
    <pubDate>Mon, 14 Aug 2023 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-38687</strong></p>
  <p>Svelecte is a flexible autocomplete/select component written in Svelte. Svelecte item names are rendered as raw HTML with no escaping. This allows the injection of arbitrary HTML into the Svelecte dropdown. This can be exploited to execute arbitrary JavaScript whenever a Svelecte dropdown is opened. Item names given to Svelecte appear to be directly rendered as HTML by the default item renderer.…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-25875 – The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) du...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25875</guid>
    <pubDate>Tue, 12 Jul 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-25875</strong></p>
  <p>The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29261 – The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29261</guid>
    <pubDate>Mon, 05 Apr 2021 07:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29261</strong></p>
  <p>The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29261">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
