svelte
sveltejs- Product type
- Other
- Catalog vulnerabilities
- 10
Severity across 10 analyzed records
Verify to analyze this security profile
en
As of 09/19/2026, within CyStack's analyzed data, svelte has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of svelte and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-42599Cross-site scripting via spread attributes in Svelte SSR | Exploitation statusNot known exploited | FixYes | Published06/09/2026 | SeverityMedium |
CVE-2026-42567Svelte: ReDoS in `<svelte:element>` Tag Validation | Exploitation statusNot known exploited | FixYes | Published06/09/2026 | SeverityMedium |
CVE-2026-42573Svelte: XSS via DOM Clobbering of Internal Framework State | Exploitation statusNot known exploited | FixYes | Published06/09/2026 | SeverityMedium |
CVE-2026-27902Svelte Vulnerable to XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers | Exploitation statusNot known exploited | FixNot confirmed | Published02/26/2026 | SeverityMedium |
CVE-2026-27901Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent` | Exploitation statusNot known exploited | FixNot confirmed | Published02/26/2026 | SeverityMedium |
CVE-2026-27125Svelte SSR attribute spreading includes inherited properties from prototype chain | Exploitation statusNot known exploited | FixYes | Published02/20/2026 | SeverityMedium |
CVE-2026-27122Svelte SSR does not validate dynamic element tag names in `<svelte:element>` | Exploitation statusNot known exploited | FixYes | Published02/20/2026 | SeverityMedium |
CVE-2026-27121Svelte affected by cross-site scripting via spread attributes in Svelte SSR | Exploitation statusNot known exploited | FixYes | Published02/20/2026 | SeverityMedium |
CVE-2026-27119Svelte affected by XSS in SSR `<option>` element | Exploitation statusNot known exploited | FixYes | Published02/20/2026 | SeverityMedium |
CVE-2024-45047Potential mXSS vulnerability due to improper HTML escaping in svelte | Exploitation statusPublic exploit | FixNot confirmed | Published08/30/2024 | SeverityMedium |