Nitropack provides a web-performance optimization platform centered on a single product offering, with the durable signal concentrated on web-application layer vulnerabilities including cross-site request forgery and code-injection issues. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nitropack over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43922CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7. | Aug 29, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-52121HIGH Cross-Site Request Forgery (CSRF) vulnerability in NitroPack Inc. NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images.This issue af | Jan 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2026-39669MEDIUM Missing Authorization vulnerability in NitroPack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NitroPack: from n/a through 1.19.3. | Apr 8, 2026 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nitropack.
Media articles that mention a CVE ID that affects a product developed by Nitropack — matched by CVE ID, not by vendor name.