Every CVE whose affected-product data names Svelte Sveltekit, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (10)
CVE-2023-29003 — CVSS 8.8 (high): SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs. This is done by…
CVE-2023-29008 — CVSS 8.8 (high): The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing…
CVE-2026-82261 — CVSS 7.5 (high): SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion…
CVE-2026-82259 — CVSS 7.5 (high): SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote…
CVE-2026-82260 — CVSS 7.5 (high): SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled…
CVE-2024-53261 — CVSS 5.4 (medium): SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input from *the request URL*…
CVE-2024-53262 — CVSS 5.4 (medium): SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html template for errors…
CVE-2026-82256 — CVSS 5.3 (medium): SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by…
CVE-2026-82258 — CVSS 4.8 (medium): SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users…
CVE-2026-82257 — CVSS 4.3 (medium): SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept…