Packs ECMAScript/CommonJs/AMD modules for the browser. Allows you to split your codebase into multiple bundles, which can be loaded on demand. Supports loaders to preprocess files, i.e. json, jsx, es7, css, less, ... and your custom stuff.
91%
Total Score
60
100
100
95
100
| Title | Versions | Severity |
|---|---|---|
CVE-2025-68458 webpack is vulnerable to Server-Side Request Forgery (SSRF) in versions 5.49.0 - 5.104.0. | 5.49.0 - 5.104.0 | Low |
CVE-2025-68157 webpack is vulnerable to Server-Side Request Forgery (SSRF) in versions 5.49.0 - 5.104.0. | 5.49.0 - 5.104.0 | Low |
AIKIDO-2025-10967 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. webpack is vulnerable to Server-Side Request Forgery (SSRF) in versions 5.49.0 - 5.103.0. | 5.49.0 - 5.103.0 | Medium |
AIKIDO-2025-10746 webpack is vulnerable to Improper Access Control in versions 5.0.0 - 5.75.0. | 5.0.0 - 5.75.0 | Medium |
AIKIDO-2024-10289 webpack is vulnerable to Cross-site Scripting (XSS) in versions 5.0.0 - 5.93.0. | 5.0.0 - 5.93.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
acorn Version ^8.16.0 | — | — |
events Version ^3.2.0 | — | — |
mime-db Version ^1.54.0 | — | — |
tapable Version ^2.3.0 | — | — |
neo-async Version ^2.6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant