Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-16
4 active CVEs reported via OSV.dev
Qwik has a potential mXSS vulnerability due to improper HTML escaping
builderio/qwik is vulnerable to code injection
@builder.io/qwik vulnerable to Cross-site Scripting
Qwik vulnerable to Unauthenticated RCE via server$ Deserialization
Get SLA-backed support, security patches, and direct access to senior engineers for Qwik — without relying on volunteer maintainers.
Talk to an Expert →