Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/nuxt — 8 CVEs · VulnScope
pkg:npm/
nuxt
8 total CVEs
HIGH
3
MEDIUM
1
LOW
1
✅ Check your installed version
Check
All known vulnerabilities
HIGH
8.8
CVE-2024-34344
Nuxt vulnerable to remote code execution via the browser when running the test locally
>= 3.4.0, < 3.12.4
HIGH
8.1
CVE-2023-3224
nuxt Code Injection vulnerability
>= 3.4.0, < 3.4.3
HIGH
7.5
CVE-2025-27415
Nuxt allows DOS via cache poisoning with payload rendering response
>= 3.0.0, < 3.16.0
MEDIUM
6.3
nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR
from 0, < 3.12.4
LOW
3.1
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
>= 3.6.0, < 3.19.0
—
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
>= 3.11.0, < 3.21.6
—
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
>= 3.1.0, < 3.21.6
—
Nuxt: Reflected XSS in `navigateTo()` external redirect
>= 3.4.3, < 3.21.6
CVE-2024-34343
CVE-2025-59414
CVE-2026-47200
CVE-2026-46342
CVE-2026-45669