Skip to content
Noroxi

qwik records

11 published records for vendor qwik.

All records

11 records
  • Prototype Pollution via FormData Processing in Qwik City

    CriticalCVSS 10.0No exploitEPSS 1%

    qwik · qwikFeb 3, 2026

  • CVE-2023-1283
    39Monitor

    Code Injection in builderio/qwik

    CriticalCVSS 9.8No exploitEPSS 1%

    qwik · qwikMar 8, 2023

  • Qwik affected by unauthenticated RCE via server$ Deserialization

    CriticalCVSS 9.2Proof of conceptEPSS 3%

    qwik · qwikMar 3, 2026

  • Qwik has array method pollution in FormData processing, allowing type confusion and DoS

    HighCVSS 7.5No exploitEPSS 1%

    qwik · qwikMar 20, 2026

  • [qwik-city] CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)

    HighCVSS 7.1No exploitEPSS 0%

    qwik · qwikFeb 3, 2026

  • CVE-2023-2307
    26Monitor

    Cross-Site Request Forgery (CSRF) in builderio/qwik

    MediumCVSS 6.5No exploitEPSS 0%

    qwik · qwikApr 26, 2023

  • Cross-site Scripting (XSS) vulnerability due to improper HTML escaping in qwik

    MediumCVSS 6.1No exploitEPSS 0%

    qwik · qwikAug 6, 2024

  • CVE-2023-0410
    24Monitor

    Cross-site Scripting (XSS) - Generic in builderio/qwik

    MediumCVSS 6.1No exploitEPSS 0%

    qwik · qwikJan 19, 2023

  • Qwik City has a CSRF Protection Bypass via Content-Type Header Validation

    MediumCVSS 5.9No exploitEPSS 0%

    qwik · qwikFeb 3, 2026

  • Qwik SSR XSS via Unsafe Virtual Node Serialization

    MediumCVSS 5.3No exploitEPSS 0%

    qwik · qwikFeb 3, 2026

  • Qwik City Open Redirect via fixTrailingSlash

    LowCVSS 2.7No exploitEPSS 0%

    qwik · qwikFeb 3, 2026