| CVE-2026-45669 |
medium |
— |
5.5 |
|
|
|
16d ago |
Nuxt: Reflected XSS in `navigateTo()` external redirect |
| CVE-2026-46342 |
low |
— |
2.5 |
|
|
|
15d ago |
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning |
| CVE-2026-47200 |
unknown |
— |
— |
|
|
|
5d ago |
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*` |
| CVE-2025-59414 |
unknown |
— |
— |
|
|
|
9mo ago |
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival |
| CVE-2025-27415 |
unknown |
— |
— |
|
|
|
1y ago |
Nuxt allows DOS via cache poisoning with payload rendering response |
| CVE-2024-34344 |
unknown |
— |
— |
|
|
|
2y ago |
Nuxt vulnerable to remote code execution via the browser when running the test locally |
| CVE-2024-34343 |
unknown |
— |
— |
|
|
|
2y ago |
nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR |
| CVE-2023-3224 |
unknown |
— |
— |
|
|
|
3y ago |
nuxt Code Injection vulnerability |