CRAIR CRA Readiness Snapshot

kuaifan/dootask · composer.lock + package.json · 4 Sep 2026, 22:10 UTC
0 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
213
dependencies in scope
167
known vulnerabilities
2
actively exploited (CISA KEV)
99.0%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

From 11 September 2026, an actively exploited vulnerability in software you ship must be reported to ENISA within 24 hours of awareness (CRA Art. 14). In this snapshot, 2 findings are in the CISA KEV catalog (0 in production dependencies):

PackageYour versionCVEFixed inExploit context
jquery dev ^3.6.4 (unpinned) CVE-2020-11023 3.5.0 KEV listed 2025-01-23
vite dev ^2.9.15 (unpinned) CVE-2025-31125 6.2.4 KEV listed 2026-01-22

⚠ No lockfile — SBOM is not reproducible

This scan is based on a manifest (composer.lock, package.json), not a lockfile. 60 of 213 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.

All findings (167)

PackageVersionAdvisorySeverityEPSSFixed inSummary
jquery dev ^3.6.4 CVE-2020-11022 MODERATE 99.0% 3.5.0 Potential XSS vulnerability in jQuery
jquery dev ^3.6.4 CVE-2019-11358 MODERATE 87.2% 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
vite dev ^2.9.15 CVE-2025-30208 MODERATE 75.0% 6.2.3 Vite bypasses server.fs.deny when using ?raw??
vite dev ^2.9.15 CVE-2025-31486 MODERATE 40.2% 6.2.5 Vite allows server.fs.deny to be bypassed with .svg or relative paths
jquery dev ^3.6.4 CVE-2015-9251 MODERATE 29.7% 1.12.2 Cross-Site Scripting (XSS) in jquery
lodash dev ^4.17.21 CVE-2021-23337 HIGH 21.3% 4.17.21 Command Injection in lodash
lodash dev ^4.17.21 CVE-2021-23337 HIGH 21.3% 4.18.0 lodash vulnerable to Code Injection via `_.template` imports key names
jquery dev ^3.6.4 CVE-2011-4969 MODERATE 19.2% 1.6.3 jQuery vulnerable to Cross-Site Scripting (XSS)
jquery dev ^3.6.4 CVE-2012-6708 MODERATE 8.6% 1.9.0 Cross-Site Scripting in jquery
axios dev ^1.8.4 CVE-2021-3749 HIGH 8.5% 0.21.2 axios Inefficient Regular Expression Complexity vulnerability
lodash dev ^4.17.21 CVE-2020-28500 MODERATE 7.3% 4.17.21 Regular Expression Denial of Service (ReDoS) in lodash
jquery dev ^3.6.4 CVE-2020-7656 MODERATE 6.3% 1.9.0 Cross-Site Scripting in jquery
axios dev ^1.8.4 CVE-2019-10742 HIGH 6.0% 0.18.1 Denial of Service in axios
codemirror dev ^5.65.16 CVE-2020-7760 MODERATE 5.3% 5.58.2 Regular expression denial of service in codemirror
lodash dev ^4.17.21 CVE-2020-8203 HIGH 5.2% 4.17.19 Prototype Pollution in lodash
lodash dev ^4.17.21 CVE-2019-10744 CRITICAL 5.0% 4.17.12 Prototype Pollution in lodash
postcss dev ^8.4.5 CVE-2021-23368 MODERATE 3.5% 7.0.36 Regular Expression Denial of Service in postcss
vite dev ^2.9.15 CVE-2026-39363 HIGH 3.4% 8.0.5 Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
prismjs dev ^1.29.0 CVE-2021-23341 HIGH 3.2% 1.23.0 Denial of service in prismjs
vite dev ^2.9.15 CVE-2023-34092 HIGH 3.1% 2.9.16 Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
lodash dev ^4.17.21 CVE-2019-1010266 MODERATE 3.1% 4.17.11 Regular Expression Denial of Service (ReDoS) in lodash
jquery dev ^3.6.4 CVE-2016-10707 HIGH 2.9% 3.0.0 Denial of Service in jquery
axios dev ^1.8.4 CVE-2026-25639 HIGH 2.7% 1.13.5 Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
jspdf dev ^2.5.1 CVE-2021-23353 HIGH 2.6% 2.3.1 jspdf vulnerable to Regular Expression Denial of Service (ReDoS)
postcss dev ^8.4.5 CVE-2021-23382 MODERATE 2.5% 8.2.13 Regular Expression Denial of Service in postcss
lodash dev ^4.17.21 CVE-2018-3721 MODERATE 2.4% 4.17.5 Prototype Pollution in lodash
axios dev ^1.8.4 CVE-2020-28168 MODERATE 2.3% 0.21.1 Axios vulnerable to Server-Side Request Forgery
markdown-it dev ^14.1.0 CVE-2022-21670 MODERATE 2.2% 12.3.2 Uncontrolled Resource Consumption in markdown-it
jspdf dev ^2.5.1 CVE-2025-68428 CRITICAL 2.2% 4.0.0 jsPDF has Local File Inclusion/Path Traversal vulnerability
vite dev ^2.9.15 CVE-2026-39364 HIGH 2.1% 8.0.5 Vite: `server.fs.deny` bypassed with queries

+ 137 further findings (mostly lower severity) — available in the full export.

SBOM summary

213 direct dependencies scanned (153 pinned to exact versions) from composer.lock, package.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us