Svelte
19 known vulnerabilities
Top Products
Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes f
Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the
Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the S
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, redir
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the
Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly esca
Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textConte
svelte performance oriented web framework. Prior to 5.51.5, in server-side rendering, attribute spreading on elements (e
svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side render
svelte performance oriented web framework. Versions of svelte prior to 5.51.5 are vulnerable to cross-site scripting (XS
svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering ou
An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4,
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, Svelt
Frequently Asked Questions
How many CVEs affect Svelte?
Svelte has 19 CVE records in our database, including 2 critical and 8 high severity vulnerabilities.
What are the most severe Svelte vulnerabilities?
Svelte has 2 critical severity (CVSS 9.0+) and 8 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Svelte vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Svelte products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Svelte Vulnerabilities
CyberStrike scans your infrastructure for Svelte vulnerabilities and provides real-time remediation guidance.
Get Started