Qwik is a modestly represented framework within the vulnerability landscape, yet occupies a position more prominent than most, driven by its role as a web and application development platform where its disclosures concentrate in a single product line. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, clustered around web-layer input-handling and object-manipulation weaknesses including cross-site request forgery, cross-site scripting, prototype pollution, type confusion, and untrusted deserialization that are characteristic of JavaScript and framework-level flaws. Current severity, exploitation, and public-exploit availability are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qwik over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27971CRITICAL Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any u | Mar 3, 2026 | 9.8 | 49 | NO | YES |
CVE-2026-25150CRITICAL Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city mid | Feb 3, 2026 | 10.0 | 32 | NO | NO |
CVE-2023-1283CRITICAL Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
| Mar 8, 2023 | 9.8 | 32 | NO | NO |
CVE-2026-32701HIGH Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form field names during FormData parsing. By submitting mixed ar | Mar 20, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-25155HIGH Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type | Feb 3, 2026 | 7.1 | 24 | NO | NO |
CVE-2026-25148MEDIUM Qwik is a performance focused javascript framework. Prior to version 1.19.0, a Cross-Site Scripting vulnerability in Qwik.js' server-side rendering virtual attribute serialization | Feb 3, 2026 | 6.1 | 22 | NO | NO |
CVE-2023-2307MEDIUM Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.
| Apr 26, 2023 | 6.5 | 22 | NO | NO |
CVE-2026-25151MEDIUM Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inconsistently interprets HTTP request headers, which can be ab | Feb 3, 2026 | 5.9 | 21 | NO | NO |
CVE-2026-25149MEDIUM Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler middleware allows a remote attack | Feb 3, 2026 | 6.1 | 21 | NO | NO |
CVE-2023-0410MEDIUM Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5. | Jan 20, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qwik.
Media articles that mention a CVE ID that affects a product developed by Qwik — matched by CVE ID, not by vendor name.