Declarative routing for React
93%
Total Score
63
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2025-59057 react-router is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 7.0.0 - 7.8.2. | 7.0.0 - 7.8.2 | High |
CVE-2026-21884 react-router is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 7.0.0 - 7.12.0. | 7.0.0 - 7.12.0 | High |
CVE-2026-22030 react-router is vulnerable to Origin Validation Error in versions 7.0.0 - 7.11.0. | 7.0.0 - 7.11.0 | Medium |
CVE-2026-22029 react-router is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 7.0.0 - 7.11.0. | 7.0.0 - 7.11.0 | High |
CVE-2025-68470 react-router is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 6.0.0 - 6.30.2 and 7.0.0 - 7.9.6. | 6.0.0 - 6.30.27.0.0 - 7.9.6 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
cookie Version ^1.0.1 | — | — |
set-cookie-parser Version ^2.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant