Swiperjs is a JavaScript touch slider library that, despite a minimal vulnerability footprint, achieves notable prominence due to its widespread embedding in web applications and mobile frameworks. The observed weakness centers on prototype-pollution conditions, which are characteristic of JavaScript object-manipulation contexts and reflect the inherent risks of dynamic property assignment in the language. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Swiperjs over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23370CRITICAL This affects the package swiper before 6.5.1. | Apr 12, 2021 | 9.8 | 29 | NO | NO |
CVE-2026-27212HIGH Swiper is a free and mobile touch slider with hardware accelerated transitions and native behavior. Versions 6.5.1 through 12.1.1 have a Prototype pollution vulnerability. The vuln | Feb 21, 2026 | 7.8 | 28 | NO | NO |
CVE-2024-39000MEDIUM adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Den | Jul 1, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-38997MEDIUM adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vulnerability allows attackers to execute arbitrary code or ca | Jul 1, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-39853MEDIUM adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Deni | Jul 1, 2024 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Swiperjs.
Media articles that mention a CVE ID that affects a product developed by Swiperjs — matched by CVE ID, not by vendor name.