Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nuxt

First CVE: Dec 12, 2022Active for: 4 yearsTotal CVEs: 25
29.6
VTI Score
Low

Nuxt is a Vue.js framework and meta-framework for building web applications, distributed across a concentrated product portfolio that includes the core framework, tooling such as devtools and og_image generation, and related ecosystem components. Despite its narrow vendor footprint, the framework occupies a prominent position in the modern JavaScript development landscape due to widespread adoption in production applications. The vulnerability exposure concentrates on application-layer and code-generation concerns: cross-site scripting and input-neutralization flaws, code injection through improper generation controls, path traversal in file-handling routines, and acceptance of extraneous untrusted data mixed with trusted inputs—weakness classes that reflect the framework's role in bridging client and server rendering, templating, and dynamic code execution. Defenders tracking applications built on this framework should prioritize updates to the core framework and development tooling, since flaws in the build or rendering layer can propagate broadly to dependent projects. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nuxt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 2022
3 years ago
Most Recent CVE
Jun 23, 2026
32 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-3224CRITICAL
Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.
Jun 13, 20239.863NONO
CVE-2026-53721HIGH
Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensi
Jun 12, 20268.231NONO
CVE-2026-56317MEDIUM
Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping.
Jun 20, 20266.129NONO
CVE-2026-56326MEDIUM
Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validate path-normalized payloads like
Jun 22, 20266.127NONO
CVE-2026-34404HIGH
Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contai
Mar 31, 20267.527NONO
CVE-2026-56301MEDIUM
Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abstract-namespace Unix socket witho
Jun 23, 20265.525NONO
CVE-2026-56698MEDIUM
Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open option, allowing client-side script execution. Attackers can supp
Jun 22, 20266.125NONO
CVE-2026-56697MEDIUM
Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass the script-protocol check but res
Jun 22, 20266.125NONO
CVE-2024-34344HIGH
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestC
Aug 5, 20248.825NONO
CVE-2024-23657HIGH
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC fu
Aug 5, 20248.825NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
68%
24%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (4.0%)
Network23 (92.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (4.0%)
Attack Complexity
Low24 (96.0%)
High1 (4.0%)
Unknown0 (0.0%)
User Interaction
None7 (28.0%)
Unknown0 (0.0%)
Required18 (72.0%)
Privileges Required
Low1 (4.0%)
High0 (0.0%)
None24 (96.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nuxt.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nuxt — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nuxt's Products

View all 4 CNAs →

Top CWEs