CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
From 11 September 2026, an actively exploited vulnerability in software you ship must be reported to ENISA within 24 hours of awareness (CRA Art. 14). In this snapshot, 2 findings are in the CISA KEV catalog (0 in production dependencies):
| Package | Your version | CVE | Fixed in | Exploit context |
|---|---|---|---|---|
| jquery dev | ^3.6.4 (unpinned) | CVE-2020-11023 | 3.5.0 | KEV listed 2025-01-23 |
| vite dev | ^2.9.15 (unpinned) | CVE-2025-31125 | 6.2.4 | KEV listed 2026-01-22 |
⚠ No lockfile — SBOM is not reproducible
This scan is based on a manifest (composer.lock, package.json), not a lockfile. 60 of 213 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.
All findings (167)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| jquery dev | ^3.6.4 | CVE-2020-11022 | MODERATE | 99.0% | 3.5.0 | Potential XSS vulnerability in jQuery |
| jquery dev | ^3.6.4 | CVE-2019-11358 | MODERATE | 87.2% | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| vite dev | ^2.9.15 | CVE-2025-30208 | MODERATE | 75.0% | 6.2.3 | Vite bypasses server.fs.deny when using ?raw?? |
| vite dev | ^2.9.15 | CVE-2025-31486 | MODERATE | 40.2% | 6.2.5 | Vite allows server.fs.deny to be bypassed with .svg or relative paths |
| jquery dev | ^3.6.4 | CVE-2015-9251 | MODERATE | 29.7% | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| lodash dev | ^4.17.21 | CVE-2021-23337 | HIGH | 21.3% | 4.17.21 | Command Injection in lodash |
| lodash dev | ^4.17.21 | CVE-2021-23337 | HIGH | 21.3% | 4.18.0 | lodash vulnerable to Code Injection via `_.template` imports key names |
| jquery dev | ^3.6.4 | CVE-2011-4969 | MODERATE | 19.2% | 1.6.3 | jQuery vulnerable to Cross-Site Scripting (XSS) |
| jquery dev | ^3.6.4 | CVE-2012-6708 | MODERATE | 8.6% | 1.9.0 | Cross-Site Scripting in jquery |
| axios dev | ^1.8.4 | CVE-2021-3749 | HIGH | 8.5% | 0.21.2 | axios Inefficient Regular Expression Complexity vulnerability |
| lodash dev | ^4.17.21 | CVE-2020-28500 | MODERATE | 7.3% | 4.17.21 | Regular Expression Denial of Service (ReDoS) in lodash |
| jquery dev | ^3.6.4 | CVE-2020-7656 | MODERATE | 6.3% | 1.9.0 | Cross-Site Scripting in jquery |
| axios dev | ^1.8.4 | CVE-2019-10742 | HIGH | 6.0% | 0.18.1 | Denial of Service in axios |
| codemirror dev | ^5.65.16 | CVE-2020-7760 | MODERATE | 5.3% | 5.58.2 | Regular expression denial of service in codemirror |
| lodash dev | ^4.17.21 | CVE-2020-8203 | HIGH | 5.2% | 4.17.19 | Prototype Pollution in lodash |
| lodash dev | ^4.17.21 | CVE-2019-10744 | CRITICAL | 5.0% | 4.17.12 | Prototype Pollution in lodash |
| postcss dev | ^8.4.5 | CVE-2021-23368 | MODERATE | 3.5% | 7.0.36 | Regular Expression Denial of Service in postcss |
| vite dev | ^2.9.15 | CVE-2026-39363 | HIGH | 3.4% | 8.0.5 | Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket |
| prismjs dev | ^1.29.0 | CVE-2021-23341 | HIGH | 3.2% | 1.23.0 | Denial of service in prismjs |
| vite dev | ^2.9.15 | CVE-2023-34092 | HIGH | 3.1% | 2.9.16 | Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//) |
| lodash dev | ^4.17.21 | CVE-2019-1010266 | MODERATE | 3.1% | 4.17.11 | Regular Expression Denial of Service (ReDoS) in lodash |
| jquery dev | ^3.6.4 | CVE-2016-10707 | HIGH | 2.9% | 3.0.0 | Denial of Service in jquery |
| axios dev | ^1.8.4 | CVE-2026-25639 | HIGH | 2.7% | 1.13.5 | Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig |
| jspdf dev | ^2.5.1 | CVE-2021-23353 | HIGH | 2.6% | 2.3.1 | jspdf vulnerable to Regular Expression Denial of Service (ReDoS) |
| postcss dev | ^8.4.5 | CVE-2021-23382 | MODERATE | 2.5% | 8.2.13 | Regular Expression Denial of Service in postcss |
| lodash dev | ^4.17.21 | CVE-2018-3721 | MODERATE | 2.4% | 4.17.5 | Prototype Pollution in lodash |
| axios dev | ^1.8.4 | CVE-2020-28168 | MODERATE | 2.3% | 0.21.1 | Axios vulnerable to Server-Side Request Forgery |
| markdown-it dev | ^14.1.0 | CVE-2022-21670 | MODERATE | 2.2% | 12.3.2 | Uncontrolled Resource Consumption in markdown-it |
| jspdf dev | ^2.5.1 | CVE-2025-68428 | CRITICAL | 2.2% | 4.0.0 | jsPDF has Local File Inclusion/Path Traversal vulnerability |
| vite dev | ^2.9.15 | CVE-2026-39364 | HIGH | 2.1% | 8.0.5 | Vite: `server.fs.deny` bypassed with queries |
+ 137 further findings (mostly lower severity) — available in the full export.
SBOM summary
213 direct dependencies scanned (153 pinned to exact versions) from composer.lock, package.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.