Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-47843 |
|
Vulnerability in react (CVE-2026-47843)
vulnerability in react (CVE-2026-47843). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-80426 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-80426)
cross-site scripting in react (CVE-2026-80426). Confidential information can be exposed externally.
|
| CVE-2026-55850 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-55850)
cross-site scripting in react (CVE-2026-55850). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62681 |
|
Code Injection in react (CVE-2026-62681)
code injection in react (CVE-2026-62681). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63642 |
|
SSRF (Server-Side Request Forgery) in magicmirror (CVE-2026-63642)
SSRF in magicmirror (CVE-2026-63642). Risk of unauthorized operations or information disclosure. Exploitable via ``CHECK_ARTICLE_URL``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-73155 |
|
Vulnerability in react (CVE-2026-73155)
vulnerability in react (CVE-2026-73155). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48161 |
|
Vulnerability in react (CVE-2026-48161)
vulnerability in react (CVE-2026-48161). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| CVE-2026-48160 |
|
Vulnerability in react (CVE-2026-48160)
vulnerability in react (CVE-2026-48160). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| CVE-2026-48159 |
|
Vulnerability in react (CVE-2026-48159)
vulnerability in react (CVE-2026-48159). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| CVE-2026-48158 |
|
Vulnerability in react (CVE-2026-48158)
vulnerability in react (CVE-2026-48158). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| CVE-2026-19323 |
|
Path Traversal in react (CVE-2026-19323)
path traversal in react (CVE-2026-19323). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18648 |
|
Path Traversal in react (CVE-2026-18648)
path traversal in react (CVE-2026-18648). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18245 |
|
Code Injection in react (CVE-2026-18245)
code injection in react (CVE-2026-18245). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55685 |
|
Vulnerability in react-router (CVE-2026-55685)
vulnerability in react-router (CVE-2026-55685). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.18.0` or later.
|
| CVE-2024-58353 |
|
Vulnerability in react (CVE-2024-58353)
vulnerability in react (CVE-2024-58353). Confidential information can be exposed externally.
|
| CVE-2024-58355 |
|
Vulnerability in react (CVE-2024-58355)
vulnerability in react (CVE-2024-58355). Confidential information can be exposed externally. Mitigation: upgrade to `4.7.16` or later.
|
| CVE-2025-71389 |
|
Code Injection in react (CVE-2025-71389)
code injection in react (CVE-2025-71389). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53669 |
|
Open Redirect in react-router (CVE-2026-53669)
vulnerability in react-router (CVE-2026-53669). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.18.0` or later.
|
| CVE-2026-53668 |
|
Cross-Site Scripting (XSS) in react-router-dom (CVE-2026-53668)
cross-site scripting in react-router-dom (CVE-2026-53668). Confidential information can be exposed externally. Mitigation: upgrade to `7.13.0` or later.
|
| CVE-2026-53667 |
|
Cross-Site Scripting (XSS) in react-router (CVE-2026-53667)
cross-site scripting in react-router (CVE-2026-53667). Confidential information can be exposed externally. Mitigation: upgrade to `7.18.0` or later.
|
| CVE-2026-53666 |
|
Vulnerability in react-router (CVE-2026-53666)
vulnerability in react-router (CVE-2026-53666). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.18.0` or later.
|
| CVE-2026-73421 |
|
Vulnerability in next-auth (CVE-2026-73421)
vulnerability in next-auth (CVE-2026-73421). Risk of unauthorized operations or information disclosure. Exploitable via ``auth``. Mitigation: upgrade to `5.0.0-beta.32` or later.
|
| CVE-2026-64649 |
|
SSRF (Server-Side Request Forgery) in next (CVE-2026-64649)
SSRF in next (CVE-2026-64649). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64648 |
|
Vulnerability in next (CVE-2026-64648)
vulnerability in next (CVE-2026-64648). Risk of unauthorized operations or information disclosure. Exploitable via ``fetch``. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64647 |
|
Vulnerability in next (CVE-2026-64647)
vulnerability in next (CVE-2026-64647). Risk of unauthorized operations or information disclosure. Exploitable via ``fetch``. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64646 |
|
Vulnerability in next (CVE-2026-64646)
vulnerability in next (CVE-2026-64646). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64645 |
|
Open Redirect in next (CVE-2026-64645)
vulnerability in next (CVE-2026-64645). Risk of unauthorized operations or information disclosure. Exploitable via ``has``. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64644 |
|
Vulnerability in next (CVE-2026-64644)
vulnerability in next (CVE-2026-64644). Risk of unauthorized operations or information disclosure. Exploitable via ``config.images.remotePatterns``. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64643 |
|
Vulnerability in next (CVE-2026-64643)
vulnerability in next (CVE-2026-64643). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64642 |
|
Vulnerability in next (CVE-2026-64642)
vulnerability in next (CVE-2026-64642). Confidential information can be exposed externally. Exploitable via ``config.i18n.locales``. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64641 |
|
Vulnerability in next (CVE-2026-64641)
vulnerability in next (CVE-2026-64641). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-44907 |
|
Vulnerability in react-server-dom-webpack (CVE-2026-44907)
vulnerability in react-server-dom-webpack (CVE-2026-44907). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `19.2.8` or later.
|
| CVE-2026-14802 |
|
A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the...
A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the...
|
| CVE-2026-58460 |
|
Path Traversal in react (CVE-2026-58460)
path traversal in react (CVE-2026-58460). Data can be tampered with by attackers.
|
| CVE-2026-12048 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-12048)
cross-site scripting in react (CVE-2026-12048). Confidential information can be exposed externally.
|
| CVE-2026-12047 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-12047)
cross-site scripting in react (CVE-2026-12047). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53663 |
|
Cross-Site Request Forgery (CSRF) in react-router (CVE-2026-53663)
vulnerability in react-router (CVE-2026-53663). Risk of unauthorized operations or information disclosure. Exploitable via ``createBrowserRouter``. Mitigation: upgrade to `7.15.1` or later.
|
| CVE-2026-44496 |
|
Vulnerability in axios (CVE-2026-44496)
vulnerability in axios (CVE-2026-44496). Risk of unauthorized operations or information disclosure. Exploitable via ``document.cookie``. Mitigation: upgrade to `0.32.0` or later.
|
| CVE-2026-42342 |
|
Vulnerability in react-router (CVE-2026-42342)
vulnerability in react-router (CVE-2026-42342). Risk of unauthorized operations or information disclosure. Exploitable via ``createBrowserRouter``. Mitigation: upgrade to `7.15.0` or later.
|
| CVE-2026-42211 |
|
React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
|
| CVE-2026-40181 |
|
Open Redirect in react-router (CVE-2026-40181)
vulnerability in react-router (CVE-2026-40181). Risk of unauthorized operations or information disclosure. Exploitable via ``redirect``. Mitigation: upgrade to `6.30.4` or later.
|
| CVE-2026-33245 |
|
React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
|
| CVE-2026-34077 |
|
Vulnerability in react-router (CVE-2026-34077)
vulnerability in react-router (CVE-2026-34077). Risk of unauthorized operations or information disclosure. Exploitable via ``createBrowserRouter``. Mitigation: upgrade to `7.14.0` or later.
|
| CVE-2026-33244 |
|
Cross-Site Scripting (XSS) in react-router (CVE-2026-33244)
cross-site scripting in react-router (CVE-2026-33244). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `7.13.2` or later.
|
| CVE-2026-7459 |
|
Vulnerability in wordpress (CVE-2026-7459)
vulnerability in wordpress (CVE-2026-7459). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9349 |
|
Information Disclosure in react (CVE-2026-9349)
vulnerability in react (CVE-2026-9349). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30691 |
|
Cross-Site Scripting (XSS) in @cyntler/react-doc-viewer (CVE-2026-30691)
cross-site scripting in @cyntler/react-doc-viewer (CVE-2026-30691). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44501 |
|
Unsafe Deserialization in react (CVE-2026-44501)
vulnerability in react (CVE-2026-44501). Risk of unauthorized operations or information disclosure. Exploitable via `GET /callback/oidc`. Mitigation: upgrade to `1.5.0.3` or later.
|
| CVE-2026-45109 |
|
Vulnerability in next (CVE-2026-45109)
vulnerability in next (CVE-2026-45109). Confidential information can be exposed externally. Exploitable via ``middleware.ts``. Mitigation: upgrade to `16.2.6` or later.
|
| CVE-2026-44572 |
|
Vulnerability in next (CVE-2026-44572)
vulnerability in next (CVE-2026-44572). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `16.2.5` or later.
|