VendorsSveltesveltekitall versions
Vulnerabilities

Svelte Sveltekit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2023-29003
SvelteKit has Insufficient Cross-Site Request Forgery Protection
Published 2023-04-04 · Modified
8.8EPSS 0.006
CVE-2023-29008
SvelteKit framework has Insufficient CSRF protection for CORS requests
Published 2023-04-06 · Modified
8.8EPSS 0.004
CVE-2026-82259
SvelteKit 2.49.0 before 2.53.3 Denial of Service via form
Published 2026-08-28 · Analyzed
8.7EPSS 0.005
CVE-2026-82260
SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization
Published 2026-08-28 · Analyzed
8.7EPSS 0.005
CVE-2026-82261
SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization
Published 2026-08-28 · Analyzed
8.7EPSS 0.005
CVE-2026-82256
SvelteKit before 2.69.1 Denial of Service via Remote Form
Published 2026-08-28 · Analyzed
6.9EPSS 0.004
CVE-2026-82258
SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch
Published 2026-08-28 · Analyzed
5.9EPSS 0.002
CVE-2024-53262
Unescaped error message included on error page in SvelteKit
Published 2024-11-25 · Analyzed
5.4EPSS 0.005
CVE-2024-53261
Cross-Site Scripting attack (XSS) on dev mode 404 page in SvelteKit
Published 2024-11-25 · Analyzed
5.4EPSS 0.003
CVE-2026-82257
SvelteKit before 2.69.1 Prototype Pollution via File Input
Published 2026-08-28 · Analyzed
5.3EPSS 0.004