nuxt records
25 published records for vendor nuxt.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 88%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-749 Exposed Dangerous Method or Function2
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAll records
25 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2023-3224No exploit | Code Injection in nuxt/nuxtnuxt · nuxt · CWE-94 | Critical9.8 | — | 58.6% | Jun 13, 2023 |
35Monitor | CVE-2024-23657No exploit | Path Traversal: '../filedir' in Nuxt Devtoolsnuxt · nuxt · CWE-22 | High8.8 | — | 1.2% | Aug 5, 2024 |
35Monitor | CVE-2024-34344No exploit | Remote code execution via the browser when running the test locally in nuxtnuxt · nuxt · CWE-94 | High8.8 | — | 0.8% | Aug 5, 2024 |
35Monitor | CVE-2026-53721No exploit | Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matchernuxt · nuxt · CWE-178 | High8.8 | — | 0.5% | Jun 12, 2026 |
30Monitor | CVE-2024-42352No exploit | Server-Side Request Forgery (SSRF) in nuxt-iconnuxt · nuxt · CWE-918 | High7.5 | — | 0.6% | Aug 5, 2024 |
30Monitor | CVE-2025-27415Proof of concept | Nuxt allows DOS via cache poisoning with payload rendering responsenuxt · nuxt · CWE-349 | High7.5 | — | 0.4% | Mar 19, 2025 |
27Monitor | CVE-2026-34404No exploit | Nuxt OG Image vulnerable to DoS via image generationnuxt · og image · CWE-400 | Medium6.9 | — | 0.5% | Mar 31, 2026 |
27Monitor | CVE-2026-56301No exploit | Nuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on Linuxnuxt · nuxt · CWE-276 | Medium6.8 | — | 0.1% | Jun 23, 2026 |
25Monitor | CVE-2026-47200No exploit | Nuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`nuxt · nuxt · CWE-284 | Medium6.3 | — | 0.3% | Jun 12, 2026 |
24Monitor | CVE-2023-0878No exploit | Cross-site Scripting (XSS) - Generic in nuxt/frameworknuxt · nuxt · CWE-79 | Medium6.1 | — | 0.5% | Feb 16, 2023 |
24Monitor | CVE-2022-4413No exploit | Cross-site Scripting (XSS) - Reflected in nuxt/frameworknuxt · framework · CWE-79 | Medium6.1 | — | 0.5% | Dec 11, 2022 |
24Monitor | CVE-2022-4414No exploit | Cross-site Scripting (XSS) - DOM in nuxt/frameworknuxt · framework · CWE-79 | Medium6.1 | — | 0.5% | Dec 11, 2022 |
24Monitor | CVE-2024-34343No exploit | Cross-site Scripting (XSS) in navigateTo if used after SSR in nuxtnuxt · nuxt · CWE-79 | Medium6.1 | — | 0.4% | Aug 5, 2024 |
24Monitor | CVE-2026-34405No exploit | Nuxt OG Image vulnerable to reflected XSS via query parameter injection into HTML attributesnuxt · og image · CWE-79 | Medium6.1 | — | 0.3% | Mar 31, 2026 |
24Monitor | CVE-2025-52662No exploit | A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***.nuxt · devtools · CWE-79 | Medium6.1 | — | 0.2% | Nov 6, 2025 |
23Monitor | CVE-2026-45670No exploit | Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)nuxt · nuxt\/rspack-builder · CWE-749 | Medium5.9 | — | 0.4% | Jun 12, 2026 |
23Monitor | CVE-2026-49993No exploit | @nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix fornuxt · nuxt\/rspack-builder · CWE-749 | Medium5.9 | — | 0.3% | Jun 12, 2026 |
21Monitor | CVE-2026-56698No exploit | Nuxt - Cross-Site Scripting via navigateTo open Optionnuxt · nuxt · CWE-79 | Medium5.3 | — | 0.4% | Jun 22, 2026 |
21Monitor | CVE-2026-56326No exploit | Nuxt - Server-Side Open Redirect via Path-Normalization Bypass in navigateTonuxt · nuxt · CWE-601 | Medium5.3 | — | 0.4% | Jun 22, 2026 |
21Monitor | CVE-2026-56697No exploit | Nuxt - Open Redirect via Protocol-Relative Paths in reloadNuxtAppnuxt · nuxt · CWE-601 | Medium5.3 | — | 0.3% | Jun 22, 2026 |
21Monitor | CVE-2026-45669No exploit | Nuxt: Reflected XSS in `navigateTo()` external redirectnuxt · nuxt · CWE-83 | Medium5.3 | — | 0.3% | Jun 12, 2026 |
20Monitor | CVE-2026-53722No exploit | Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URLnuxt · nuxt · CWE-79 | Medium5.1 | — | 0.3% | Jun 12, 2026 |
12Monitor | CVE-2025-59414No exploit | Nuxt Client-Side Path Traversal in Nuxt Island Payload Revivalnuxt · nuxt · CWE-22 | Low3.1 | — | 0.4% | Sep 17, 2025 |
9Monitor | CVE-2026-56317No exploit | Nuxt - Cross-Site Scripting via NoScript Component Slot Contentnuxt · nuxt · CWE-79 | Low2.3 | — | 0.3% | Jun 20, 2026 |
9Monitor | CVE-2026-46342No exploit | Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoningnuxt · nuxt · CWE-79 | Low2.3 | — | 0.1% | Jun 12, 2026 |
- CVE-2023-322457Plan
Code Injection in nuxt/nuxt
CriticalCVSS 9.8No exploitEPSS 59%nuxt · nuxtJun 13, 2023
- CVE-2024-2365735Monitor
Path Traversal: '../filedir' in Nuxt Devtools
HighCVSS 8.8No exploitEPSS 1%nuxt · nuxtAug 5, 2024
- CVE-2024-3434435Monitor
Remote code execution via the browser when running the test locally in nuxt
HighCVSS 8.8No exploitEPSS 1%nuxt · nuxtAug 5, 2024
- CVE-2026-5372135Monitor
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
HighCVSS 8.8No exploitEPSS 1%nuxt · nuxtJun 12, 2026
- CVE-2024-4235230Monitor
Server-Side Request Forgery (SSRF) in nuxt-icon
HighCVSS 7.5No exploitEPSS 1%nuxt · nuxtAug 5, 2024
- CVE-2025-2741530Monitor
Nuxt allows DOS via cache poisoning with payload rendering response
HighCVSS 7.5Proof of conceptEPSS 0%nuxt · nuxtMar 19, 2025
- CVE-2026-3440427Monitor
Nuxt OG Image vulnerable to DoS via image generation
MediumCVSS 6.9No exploitEPSS 0%nuxt · og imageMar 31, 2026
- CVE-2026-5630127Monitor
Nuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on Linux
MediumCVSS 6.8No exploitEPSS 0%nuxt · nuxtJun 23, 2026
- CVE-2026-4720025Monitor
Nuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
MediumCVSS 6.3No exploitEPSS 0%nuxt · nuxtJun 12, 2026
- CVE-2023-087824Monitor
Cross-site Scripting (XSS) - Generic in nuxt/framework
MediumCVSS 6.1No exploitEPSS 1%nuxt · nuxtFeb 16, 2023
- CVE-2022-441324Monitor
Cross-site Scripting (XSS) - Reflected in nuxt/framework
MediumCVSS 6.1No exploitEPSS 1%nuxt · frameworkDec 11, 2022
- CVE-2022-441424Monitor
Cross-site Scripting (XSS) - DOM in nuxt/framework
MediumCVSS 6.1No exploitEPSS 0%nuxt · frameworkDec 11, 2022
- CVE-2024-3434324Monitor
Cross-site Scripting (XSS) in navigateTo if used after SSR in nuxt
MediumCVSS 6.1No exploitEPSS 0%nuxt · nuxtAug 5, 2024
- CVE-2026-3440524Monitor
Nuxt OG Image vulnerable to reflected XSS via query parameter injection into HTML attributes
MediumCVSS 6.1No exploitEPSS 0%nuxt · og imageMar 31, 2026
- CVE-2025-5266224Monitor
A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***.
MediumCVSS 6.1No exploitEPSS 0%nuxt · devtoolsNov 6, 2025
- CVE-2026-4567023Monitor
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
MediumCVSS 5.9No exploitEPSS 0%nuxt · nuxt\/rspack-builderJun 12, 2026
- CVE-2026-4999323Monitor
@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for
MediumCVSS 5.9No exploitEPSS 0%nuxt · nuxt\/rspack-builderJun 12, 2026
- CVE-2026-5669821Monitor
Nuxt - Cross-Site Scripting via navigateTo open Option
MediumCVSS 5.3No exploitEPSS 0%nuxt · nuxtJun 22, 2026
- CVE-2026-5632621Monitor
Nuxt - Server-Side Open Redirect via Path-Normalization Bypass in navigateTo
MediumCVSS 5.3No exploitEPSS 0%nuxt · nuxtJun 22, 2026
- CVE-2026-5669721Monitor
Nuxt - Open Redirect via Protocol-Relative Paths in reloadNuxtApp
MediumCVSS 5.3No exploitEPSS 0%nuxt · nuxtJun 22, 2026
- CVE-2026-4566921Monitor
Nuxt: Reflected XSS in `navigateTo()` external redirect
MediumCVSS 5.3No exploitEPSS 0%nuxt · nuxtJun 12, 2026
- CVE-2026-5372220Monitor
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
MediumCVSS 5.1No exploitEPSS 0%nuxt · nuxtJun 12, 2026
- CVE-2025-5941412Monitor
Nuxt Client-Side Path Traversal in Nuxt Island Payload Revival
LowCVSS 3.1No exploitEPSS 0%nuxt · nuxtSep 17, 2025
- CVE-2026-563179Monitor
Nuxt - Cross-Site Scripting via NoScript Component Slot Content
LowCVSS 2.3No exploitEPSS 0%nuxt · nuxtJun 20, 2026
- CVE-2026-463429Monitor
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
LowCVSS 2.3No exploitEPSS 0%nuxt · nuxtJun 12, 2026