Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/webpack — 4 CVEs · VulnScope
pkg:npm/
webpack
4 total CVEs
CRITICAL
1
MEDIUM
1
LOW
2
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.8
CVE-2023-28154
Cross-realm object access in Webpack 5
>= 5.0.0, < 5.76.0
MEDIUM
6.4
CVE-2024-43788
Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS
>= 5.0.0-alpha.0, < 5.94.0
LOW
3.7
CVE-2025-68458
webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior
>= 5.49.0, < 5.104.1
LOW
3.7
webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence
>= 5.49.0, < 5.104.0
CVE-2025-68157