Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Qwik

First CVE: Jan 20, 2023Active for: 4 yearsTotal CVEs: 11
47.7
VTI Score
High

Qwik is a modestly represented framework within the vulnerability landscape, yet occupies a position more prominent than most, driven by its role as a web and application development platform where its disclosures concentrate in a single product line. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, clustered around web-layer input-handling and object-manipulation weaknesses including cross-site request forgery, cross-site scripting, prototype pollution, type confusion, and untrusted deserialization that are characteristic of JavaScript and framework-level flaws. Current severity, exploitation, and public-exploit availability are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
3.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Qwik over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 20, 2023
3 years ago
Most Recent CVE
Mar 20, 2026
126 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-27971CRITICAL
Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any u
Mar 3, 20269.849NOYES
CVE-2026-25150CRITICAL
Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city mid
Feb 3, 202610.032NONO
CVE-2023-1283CRITICAL
Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
Mar 8, 20239.832NONO
CVE-2026-32701HIGH
Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form field names during FormData parsing. By submitting mixed ar
Mar 20, 20267.526NONO
CVE-2026-25155HIGH
Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type
Feb 3, 20267.124NONO
CVE-2026-25148MEDIUM
Qwik is a performance focused javascript framework. Prior to version 1.19.0, a Cross-Site Scripting vulnerability in Qwik.js' server-side rendering virtual attribute serialization
Feb 3, 20266.122NONO
CVE-2023-2307MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.
Apr 26, 20236.522NONO
CVE-2026-25151MEDIUM
Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inconsistently interprets HTTP request headers, which can be ab
Feb 3, 20265.921NONO
CVE-2026-25149MEDIUM
Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler middleware allows a remote attack
Feb 3, 20266.121NONO
CVE-2023-0410MEDIUM
Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5.
Jan 20, 20236.121NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
55%
18%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required7 (63.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Qwik.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Qwik — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Qwik's Products

View all 2 CNAs →

Top CWEs