qwik records
11 published records for vendor qwik.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-25150No exploit | Prototype Pollution via FormData Processing in Qwik Cityqwik · qwik · CWE-1321 | Critical10.0 | — | 0.7% | Feb 3, 2026 |
39Monitor | CVE-2023-1283No exploit | Code Injection in builderio/qwikqwik · qwik · CWE-94 | Critical9.8 | — | 1.1% | Mar 8, 2023 |
37Monitor | CVE-2026-27971Proof of concept | Qwik affected by unauthenticated RCE via server$ Deserializationqwik · qwik · CWE-502 | Critical9.2 | — | 2.9% | Mar 3, 2026 |
30Monitor | CVE-2026-32701No exploit | Qwik has array method pollution in FormData processing, allowing type confusion and DoSqwik · qwik · CWE-843 | High7.5 | — | 0.5% | Mar 20, 2026 |
28Monitor | CVE-2026-25155No exploit | [qwik-city] CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)qwik · qwik · CWE-352 | High7.1 | — | 0.1% | Feb 3, 2026 |
26Monitor | CVE-2023-2307No exploit | Cross-Site Request Forgery (CSRF) in builderio/qwikqwik · qwik · CWE-352 | Medium6.5 | — | 0.3% | Apr 26, 2023 |
24Monitor | CVE-2024-41677No exploit | Cross-site Scripting (XSS) vulnerability due to improper HTML escaping in qwikqwik · qwik · CWE-79 | Medium6.1 | — | 0.5% | Aug 6, 2024 |
24Monitor | CVE-2023-0410No exploit | Cross-site Scripting (XSS) - Generic in builderio/qwikqwik · qwik · CWE-79 | Medium6.1 | — | 0.5% | Jan 19, 2023 |
23Monitor | CVE-2026-25151No exploit | Qwik City has a CSRF Protection Bypass via Content-Type Header Validationqwik · qwik · CWE-352 | Medium5.9 | — | 0.2% | Feb 3, 2026 |
21Monitor | CVE-2026-25148No exploit | Qwik SSR XSS via Unsafe Virtual Node Serializationqwik · qwik · CWE-79 | Medium5.3 | — | 0.3% | Feb 3, 2026 |
10Monitor | CVE-2026-25149No exploit | Qwik City Open Redirect via fixTrailingSlashqwik · qwik · CWE-601 | Low2.7 | — | 0.3% | Feb 3, 2026 |
- CVE-2026-2515040Plan
Prototype Pollution via FormData Processing in Qwik City
CriticalCVSS 10.0No exploitEPSS 1%qwik · qwikFeb 3, 2026
- CVE-2023-128339Monitor
Code Injection in builderio/qwik
CriticalCVSS 9.8No exploitEPSS 1%qwik · qwikMar 8, 2023
- CVE-2026-2797137Monitor
Qwik affected by unauthenticated RCE via server$ Deserialization
CriticalCVSS 9.2Proof of conceptEPSS 3%qwik · qwikMar 3, 2026
- CVE-2026-3270130Monitor
Qwik has array method pollution in FormData processing, allowing type confusion and DoS
HighCVSS 7.5No exploitEPSS 1%qwik · qwikMar 20, 2026
- CVE-2026-2515528Monitor
[qwik-city] CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)
HighCVSS 7.1No exploitEPSS 0%qwik · qwikFeb 3, 2026
- CVE-2023-230726Monitor
Cross-Site Request Forgery (CSRF) in builderio/qwik
MediumCVSS 6.5No exploitEPSS 0%qwik · qwikApr 26, 2023
- CVE-2024-4167724Monitor
Cross-site Scripting (XSS) vulnerability due to improper HTML escaping in qwik
MediumCVSS 6.1No exploitEPSS 0%qwik · qwikAug 6, 2024
- CVE-2023-041024Monitor
Cross-site Scripting (XSS) - Generic in builderio/qwik
MediumCVSS 6.1No exploitEPSS 0%qwik · qwikJan 19, 2023
- CVE-2026-2515123Monitor
Qwik City has a CSRF Protection Bypass via Content-Type Header Validation
MediumCVSS 5.9No exploitEPSS 0%qwik · qwikFeb 3, 2026
- CVE-2026-2514821Monitor
Qwik SSR XSS via Unsafe Virtual Node Serialization
MediumCVSS 5.3No exploitEPSS 0%qwik · qwikFeb 3, 2026
- CVE-2026-2514910Monitor
Qwik City Open Redirect via fixTrailingSlash
LowCVSS 2.7No exploitEPSS 0%qwik · qwikFeb 3, 2026