vitejs records
16 published records for vendor vitejs.
Researcher profile
- Entered KEV
- 1 · 6.3%
- Weaponized
- 1 · 6.3%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- 297 days
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-346 Origin Validation Error1
- CWE-50 Path Equivalence: '//multiple/leading/slash'1
- CWE-23 Relative Path Traversal1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
79This week | CVE-2025-31125Weaponized | Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` queryvitejs · vite · CWE-200 | High7.5 | KEV | 64.7% | Mar 31, 2025 |
52Plan | CVE-2025-30208Proof of concept | Vite bypasses server.fs.deny when using `?raw??`vitejs · vite · CWE-200 | High7.5 | — | 74.8% | Mar 24, 2025 |
33Monitor | CVE-2026-39363Proof of concept | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocketvitejs · vite · CWE-200 | High8.2 | — | 2.6% | Apr 7, 2026 |
32Monitor | CVE-2026-39364Proof of concept | Vite has a `server.fs.deny` bypass with queriesvitejs · vite · CWE-180 | High8.2 | — | 1.5% | Apr 7, 2026 |
32Monitor | CVE-2026-53571Proof of concept | Vite: `server.fs.deny` bypass on Windows alternate pathsvitejs · vite · CWE-22 | High8.2 | — | 0.6% | Jun 22, 2026 |
31Monitor | CVE-2023-34092Proof of concept | Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)vitejs · vite · CWE-50 | High7.5 | — | 3.1% | Jun 1, 2023 |
30Monitor | CVE-2024-23331No exploit | Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystemvitejs · vite · CWE-178 | High7.5 | — | 0.8% | Jan 19, 2024 |
26Monitor | CVE-2025-24010No exploit | Vite allows any websites to send any requests to the development server and read the responsevitejs · vite · CWE-346 | Medium6.5 | — | 0.3% | Jan 20, 2025 |
25Monitor | CVE-2026-39365Proof of concept | Vite has a Path Traversal in Optimized Deps `.map` Handlingvitejs · vite · CWE-22 | Medium6.3 | — | 1.0% | Apr 7, 2026 |
25Monitor | CVE-2024-45812No exploit | DOM Clobbering gadget found in vite bundled scripts that leads to XSS in Vitevitejs · vite · CWE-79 | Medium6.4 | — | 0.6% | Sep 17, 2024 |
24Monitor | CVE-2025-46565Proof of concept | Vite's server.fs.deny bypassed with /. for files under project rootvitejs · vite · CWE-22 | Medium6.0 | — | 1.2% | May 1, 2025 |
24Monitor | CVE-2023-49293Proof of concept | Cross-site Scripting in `server.transformIndexHtml` via URL payload in vitevitejs · vite · CWE-79 | Medium6.1 | — | 1.0% | Dec 4, 2023 |
19Monitor | CVE-2024-45811No exploit | server.fs.deny bypassed when using ?import&raw in vitevitejs · vite · CWE-200 | Medium4.8 | — | 1.1% | Sep 17, 2024 |
17Monitor | CVE-2022-35204No exploit | Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.vitejs · vite · CWE-22 | Medium4.3 | — | 1.3% | Aug 18, 2022 |
9Monitor | CVE-2025-58751Proof of concept | Vite middleware may serve files starting with the same name with the public directoryvitejs · vite · CWE-22 | Low2.3 | — | 1.2% | Sep 8, 2025 |
9Monitor | CVE-2025-58752No exploit | Vite's `server.fs` settings were not applied to HTML filesvitejs · vite · CWE-23 | Low2.3 | — | 0.6% | Sep 8, 2025 |
- CVE-2025-3112579This week
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
HighCVSS 7.5KEVWeaponizedEPSS 65%vitejs · viteMar 31, 2025
- CVE-2025-3020852Plan
Vite bypasses server.fs.deny when using `?raw??`
HighCVSS 7.5Proof of conceptEPSS 75%vitejs · viteMar 24, 2025
- CVE-2026-3936333Monitor
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
HighCVSS 8.2Proof of conceptEPSS 3%vitejs · viteApr 7, 2026
- CVE-2026-3936432Monitor
Vite has a `server.fs.deny` bypass with queries
HighCVSS 8.2Proof of conceptEPSS 2%vitejs · viteApr 7, 2026
- CVE-2026-5357132Monitor
Vite: `server.fs.deny` bypass on Windows alternate paths
HighCVSS 8.2Proof of conceptEPSS 1%vitejs · viteJun 22, 2026
- CVE-2023-3409231Monitor
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
HighCVSS 7.5Proof of conceptEPSS 3%vitejs · viteJun 1, 2023
- CVE-2024-2333130Monitor
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
HighCVSS 7.5No exploitEPSS 1%vitejs · viteJan 19, 2024
- CVE-2025-2401026Monitor
Vite allows any websites to send any requests to the development server and read the response
MediumCVSS 6.5No exploitEPSS 0%vitejs · viteJan 20, 2025
- CVE-2026-3936525Monitor
Vite has a Path Traversal in Optimized Deps `.map` Handling
MediumCVSS 6.3Proof of conceptEPSS 1%vitejs · viteApr 7, 2026
- CVE-2024-4581225Monitor
DOM Clobbering gadget found in vite bundled scripts that leads to XSS in Vite
MediumCVSS 6.4No exploitEPSS 1%vitejs · viteSep 17, 2024
- CVE-2025-4656524Monitor
Vite's server.fs.deny bypassed with /. for files under project root
MediumCVSS 6.0Proof of conceptEPSS 1%vitejs · viteMay 1, 2025
- CVE-2023-4929324Monitor
Cross-site Scripting in `server.transformIndexHtml` via URL payload in vite
MediumCVSS 6.1Proof of conceptEPSS 1%vitejs · viteDec 4, 2023
- CVE-2024-4581119Monitor
server.fs.deny bypassed when using ?import&raw in vite
MediumCVSS 4.8No exploitEPSS 1%vitejs · viteSep 17, 2024
- CVE-2022-3520417Monitor
Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.
MediumCVSS 4.3No exploitEPSS 1%vitejs · viteAug 18, 2022
- CVE-2025-587519Monitor
Vite middleware may serve files starting with the same name with the public directory
LowCVSS 2.3Proof of conceptEPSS 1%vitejs · viteSep 8, 2025
- CVE-2025-587529Monitor
Vite's `server.fs` settings were not applied to HTML files
LowCVSS 2.3No exploitEPSS 1%vitejs · viteSep 8, 2025