CVE security advisories and vulnerability history for vite by vitejs.
20
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
16
Public exploits
With known exploit
6.2
Avg CVSS
2022–2026
Last updated
Overview
vitejs vite has 20 published CVE records since 2022, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 16 have a known public exploit. The average CVSS base score across scored CVEs is 6.2.
This page aggregates every publicly disclosed vulnerability (CVE) affecting vitejs vite, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of vitejs vite's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical0
High6
Medium11
Low2
1 additional CVE has no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of vitejs vite's CVEs is confirmed exploited in the wild.
Public exploits
16
16 of vitejs vite's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every vitejs vite version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about vitejs vite vulnerabilities.
How many CVEs does vitejs vite have?
vitejs vite has 20 published CVE records since 2022.
How many vitejs vite CVEs are in CISA KEV?
Yes — 1 of vitejs vite's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for vitejs vite vulnerabilities?
Yes — 16 of vitejs vite's CVEs have a known public exploit.
Which versions of vitejs vite are affected?
1,022 distinct vitejs vite versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in vitejs vite CVEs?
vitejs vite's CVEs most often map to these CWE weakness types: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), CWE-284 (Improper Access Control), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
What is the average severity of vitejs vite CVEs?
The average CVSS base score across vitejs vite's scored CVEs is 6.2.