Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webpack.Js

First CVE: Sep 21, 2018Active for: 8 yearsTotal CVEs: 15
26.1
VTI Score
Low

Webpack.js maintains a modestly represented but prominent build toolchain and development-server ecosystem that is widely integrated into JavaScript development pipelines. Vulnerabilities affecting the vendor skew toward serious outcomes and concentrate in core products such as Webpack, Webpack Dev Server, and loader utilities, with recurring exposure through dangerous method exposure, ReDoS patterns, server-side request forgery, input validation gaps, and path-traversal weaknesses that reflect the complexity of bundler plugin interfaces and file-system access in development tooling. Defenders should monitor this vendor's releases closely given the breadth of downstream projects that depend on these tools; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Webpack.Js over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2018
7 years ago
Most Recent CVE
Jul 3, 2026
21 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-37601CRITICAL
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 a
Oct 12, 20229.832NONO
CVE-2023-28154CRITICAL
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted ob
Mar 13, 20239.831NONO
CVE-2026-14631MEDIUM
webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a
Jul 3, 20265.329NONO
CVE-2026-14620MEDIUM
webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changi
Jul 3, 20264.727NONO
CVE-2026-6402MEDIUM
webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP.
May 12, 20266.527NONO
CVE-2018-14732HIGH
An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSo
Sep 21, 20187.526NONO
CVE-2022-37599HIGH
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in inter
Oct 11, 20227.525NONO
CVE-2024-29180HIGH
Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not validate the supplied URL address sufficiently before returning th
Mar 21, 20247.523NONO
CVE-2026-9595MEDIUM
Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the p
Jun 15, 20264.322NONO
CVE-2022-37603HIGH
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateNam
Oct 14, 20227.521NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
13%
47%
27%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (80.0%)
High3 (20.0%)
Unknown0 (0.0%)
User Interaction
None9 (60.0%)
Unknown0 (0.0%)
Required6 (40.0%)
Privileges Required
Low3 (20.0%)
High0 (0.0%)
None12 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webpack.Js.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webpack.Js — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webpack.Js's Products

View all 3 CNAs →

Top CWEs