Vite
Vendor:
First CVE: Aug 18, 2022 · Active for 3 years
14
Total CVEs
More Total CVEs than 91% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Vite over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2022
3 years ago
Most Recent CVE
Jun 22, 2026
32 days ago
CVE Severity & Scoring
Vite14 CVEs
50%
50%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (78.6%)
Unknown0 (0.0%)
Required3 (21.4%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None14 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-31125HIGH Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev serve | Mar 31, 2025 | 7.5 | 92 | YES | YES |
CVE-2025-30208HIGH Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite se | Mar 24, 2025 | 7.5 | 84 | NO | YES |
CVE-2026-39364HIGH Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt | Apr 7, 2026 | 7.5 | 42 | NO | YES |
CVE-2026-39363HIGH Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin | Apr 7, 2026 | 7.5 | 42 | NO | YES |
CVE-2023-34092HIGH Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash ( | Jun 1, 2023 | 7.5 | 38 | NO | YES |
CVE-2026-53571HIGH Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on | Jun 22, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-39365MEDIUM Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves fi | Apr 7, 2026 | 5.3 | 31 | NO | YES |
CVE-2025-58751MEDIUM Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypa | Sep 8, 2025 | 5.3 | 30 | NO | YES |
CVE-2023-49293MEDIUM Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL is passed in unmodified, and the | Dec 4, 2023 | 6.1 | 29 | NO | YES |
CVE-2025-46565MEDIUM Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file | May 1, 2025 | 5.3 | 27 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
1 CVE
7.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
9 CVEs
64.3% of CVEs· 99th percentile
ExploitDB
1 CVE
7.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Vite
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0.0 | 1 | 6.1 | 1.0% | 0 | 1 |
| 2.9.15 | 1 | 7.5 | 3.1% | 0 | 1 |