Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Svelte

First CVE: Apr 5, 2021Active for: 5 yearsTotal CVEs: 26
31.0
VTI Score
Low

Svelte is a lightweight web-application framework and ecosystem spanning a compiler, component library, and server-side tooling (SvelteKit, adapters, and utility packages) that has gained prominence in frontend development. The vulnerability footprint reflects the framework's exposure across web-application construction and deployment: recurring weakness classes center on cross-site scripting, request-forgery, and resource-exhaustion conditions typical of application frameworks sitting between user input and server logic. The disclosures span the core compiler and related build-chain and adapter products, capturing vulnerabilities that can propagate across projects built on the framework. Defenders using this toolchain should track releases alongside their dependency-update cycles and apply updates to framework and adapter versions; live severity and exploitation details are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Svelte over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 5, 2021
5 years ago
Most Recent CVE
Jun 9, 2026
45 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-22775HIGH
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.1.0 to 5.6.1, certain inputs can cause devalue.p
Jan 15, 20267.531NONO
CVE-2026-42570HIGH
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.par
Jun 9, 20267.530NONO
CVE-2026-40074HIGH
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, redirect, when called from inside the handle server hook with a l
Apr 10, 20267.530NONO
CVE-2026-42567HIGH
Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:e
Jun 9, 20267.528NONO
CVE-2026-22803HIGH
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote function uses a binary data fo
Jan 15, 20267.528NONO
CVE-2026-22774HIGH
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.p
Jan 15, 20267.528NONO
CVE-2025-67647CRITICAL
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a server side request forgery (SSRF) a
Jan 15, 20269.128NONO
CVE-2023-29008HIGH
The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP method
Apr 6, 20238.827NONO
CVE-2026-42599MEDIUM
Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event handler properties are included in
Jun 9, 20266.125NONO
CVE-2026-42573MEDIUM
Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to
Jun 9, 20266.125NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
50%
46%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (3.8%)
Network25 (96.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (96.2%)
High1 (3.8%)
Unknown0 (0.0%)
User Interaction
None11 (42.3%)
Unknown0 (0.0%)
Required15 (57.7%)
Privileges Required
Low6 (23.1%)
High0 (0.0%)
None20 (76.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Svelte.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Svelte — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Svelte's Products

View all 4 CNAs →

Top CWEs