The React Framework
91%
Total Score
60
100
100
95
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-45109 next is vulnerable to Authentication Bypass Using an Alternate Path or Channel in versions 15.2.0 - 15.5.18 and 16.0.0 - 16.2.6. | 15.2.0 - 15.5.1816.0.0 - 16.2.6 | High |
CVE-2026-44572 next is vulnerable to Acceptance of Extraneous Untrusted Data With Trusted Data in versions 12.2.0 - 15.5.16 and 16.0.0 - 16.2.5. | 12.2.0 - 15.5.1616.0.0 - 16.2.5 | Low |
CVE-2026-44581 next is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 13.4.0 - 15.5.16 and 16.0.0 - 16.2.5. | 13.4.0 - 15.5.1616.0.0 - 16.2.5 | Medium |
CVE-2026-44582 next is vulnerable to Use of Weak Hash in versions 13.4.6 - 15.5.16 and 16.0.0 - 16.2.5. | 13.4.6 - 15.5.1616.0.0 - 16.2.5 | Low |
CVE-2026-44580 next is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 13.0.0 - 15.5.16 and 16.0.0 - 16.2.5. | 13.0.0 - 15.5.1616.0.0 - 16.2.5 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
postcss Version 8.4.31 | — | — |
@next/env Version 16.2.7 | — | — |
styled-jsx Version 5.1.6 | — | — |
@swc/helpers Version 0.5.15 | — | — |
caniuse-lite Version ^1.0.30001579 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant