svelte vulnerable to Cross-site Scripting
Modified: 2/3/2026
package
pkg:npm/svelte
svelte vulnerable to Cross-site Scripting
Modified: 2/3/2026
Svelte has a potential mXSS vulnerability due to improper HTML escaping
Modified: 8/30/2024
Svelte: ReDoS in `<svelte:element>` Tag Validation
Modified: 6/9/2026
Svelte SSR attribute spreading includes inherited properties from prototype chain
Modified: 9/10/2026
Svelte: SSR XSS via Insecure Promise Serialization in hydratable
Modified: 5/14/2026
Svelte affected by cross-site scripting via spread attributes in Svelte SSR
Modified: 9/10/2026
svelte is vulnerable to XSS with textarea bind:value
Modified: 2/3/2026
Svelte affected by XSS in SSR `<option>` element
Modified: 2/23/2026
Svelte SSR does not validate dynamic element tag names in `<svelte:element>`
Modified: 9/10/2026
Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`
Modified: 9/10/2026
Svelte SSR vulnerable to cross-site scripting via spread attributes
Modified: 6/9/2026
Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers
Modified: 2/26/2026
Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State
Modified: 6/9/2026
Svelte vulnerable to XSS when using objects during server-side rendering
Modified: 7/8/2026