CVE-2018-18282: Zeit Next.js

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.

Affected products

  • Zeit Next.js: version 7.0.0 only; version 7.0.1 only

Published 2018-10-12. Last modified 2026-06-17.