vitejs has 2 CVEs on record. The median CVSS is 7.5 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 2
Weakness classes
Products
- vite 2
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
vitejs vulnerabilities
CVEs affecting vitejs, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-39364High· 7.5PoCVite is a frontend tooling framework for JavaScript
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query par…
▾ Midnightvitejs · viteEPSS 2.0%via NVD
CVE-2026-39363High· 7.5PoCVite is a frontend tooling framework for JavaScript
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custo…
▾ Midnightvitejs · viteEPSS 3.4%via NVD