QwikDev
- Products in analyzed data
- 1
- Catalog vulnerabilities
- 9
Severity across 9 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 9 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 9 vulnerability records associated with QwikDev.
Among the 9 records analyzed by CyStack, 4 are High or Critical and 0 appear in the CISA KEV catalog for priority remediation.
The list below is based on vulnerabilities that have been viewed and analyzed; it does not represent the complete global vulnerability corpus. Use the product filter to narrow the scope.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-32701Qwik has array method pollution in FormData processing, allowing type confusion and DoS | Exploitation statusNot known exploited | FixYes | Affected productqwik | Published03/20/2026 | SeverityHigh |
CVE-2026-27971Qwik affected by unauthenticated RCE via server$ Deserialization | Exploitation statusNot known exploited | FixYes | Affected productqwik | Published03/03/2026 | SeverityCritical |
CVE-2026-25150Prototype Pollution via FormData Processing in Qwik City | Exploitation statusNot known exploited | FixYes | Affected productqwik | Published02/03/2026 | SeverityCritical |
CVE-2026-25148Qwik SSR XSS via Unsafe Virtual Node Serialization | Exploitation statusNot known exploited | FixYes | Affected productqwik | Published02/03/2026 | SeverityMedium |
CVE-2026-25151Qwik City has a CSRF Protection Bypass via Content-Type Header Validation | Exploitation statusNot known exploited | FixYes | Affected productqwik | Published02/03/2026 | SeverityMedium |
CVE-2026-25155[qwik-city] CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data) | Exploitation statusNot known exploited | FixYes | Affected productqwik | Published02/03/2026 | SeverityMedium |
CVE-2026-25149Qwik City Open Redirect via fixTrailingSlash | Exploitation statusNot known exploited | FixYes | Affected productqwik | Published02/03/2026 | SeverityLow |
CVE-2025-53620Crashing any Qwik Server | Exploitation statusPublic exploit | FixYes | Affected productqwik | Published07/09/2025 | SeverityCritical |
CVE-2024-41677Cross-site Scripting (XSS) vulnerability due to improper HTML escaping in qwik | Exploitation statusPublic exploit | FixYes | Affected productqwik | Published08/06/2024 | SeverityMedium |