Vite

Vendor:

First CVE: Aug 18, 2022 · Active for 3 years

14
Total CVEs
More Total CVEs than 91% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Vite over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2022
3 years ago
Most Recent CVE
Jun 22, 2026
32 days ago

CVE Severity & Scoring

Vite14 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (78.6%)
Unknown0 (0.0%)
Required3 (21.4%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None14 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev serve
Mar 31, 20257.592YESYES
Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite se
Mar 24, 20257.584NOYES
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt
Apr 7, 20267.542NOYES
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin
Apr 7, 20267.542NOYES
Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (
Jun 1, 20237.538NOYES
Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on
Jun 22, 20267.535NONO
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves fi
Apr 7, 20265.331NOYES
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypa
Sep 8, 20255.330NOYES
Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL is passed in unmodified, and the
Dec 4, 20236.129NOYES
Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file
May 1, 20255.327NOYES

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
1 CVE
7.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
9 CVEs
64.3% of CVEs· 99th percentile
ExploitDB
1 CVE
7.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Vite

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.0.016.11.0%01
2.9.1517.53.1%01