VendorsWebpack.jswebpackany version
Vulnerabilities

Webpack.js Webpack any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-28154
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
Published 2023-03-13 · Modified
9.8EPSS 0.014
CVE-2024-43788
DOM Clobbering Gadget found in Webpack's AutoPublicPathRuntimeModule that leads to Cross-site Scripting (XSS)
Published 2024-08-27 · Modified
6.4EPSS 0.010
CVE-2025-68157
webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects
Published 2026-02-05 · Analyzed
3.7EPSS 0.002
CVE-2025-68458
webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior
Published 2026-02-05 · Analyzed
3.7EPSS 0.002