Vulnerabilities

Last updated 1 hour ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
handlebars Handlebars: JavaScript Injection via Own Property Check Bypass Critical 9.5 6 hours ago 6 hours ago
handlebars Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates Medium Risk 4.7 6 hours ago 6 hours ago
handlebars Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation High Risk 7.5 6 months ago 28 days ago
handlebars Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial High Risk 8.1 6 months ago 28 days ago
handlebars Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options High Risk 8.2 6 months ago 28 days ago
handlebars Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry Medium Risk 4.8 6 months ago 28 days ago
handlebars Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection Medium Risk 4.7 6 months ago 28 days ago
handlebars Handlebars.js has JavaScript Injection via AST Type Confusion Critical 9.8 6 months ago 28 days ago
handlebars Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block High Risk 8.1 6 months ago 28 days ago
handlebars Handlebars.js has a Property Access Validation Bypass in container.lookup Low Risk 3.7 6 months ago 28 days ago
handlebars Prototype Pollution in handlebars Critical 9.8 6 years ago 28 days ago
handlebars Arbitrary Code Execution in Handlebars High Risk 8.1 4 years ago 28 days ago
handlebars Remote code execution in handlebars when compiling templates Critical 9.8 5 years ago 28 days ago
org.webjars.bowergithub.wycats:handlebars.js Remote code execution in handlebars when compiling templates Critical 9.8 5 years ago 28 days ago
org.webjars:handlebars Remote code execution in handlebars when compiling templates Critical 9.8 5 years ago 28 days ago
org.webjars.npm:handlebars Remote code execution in handlebars when compiling templates Critical 9.8 5 years ago 28 days ago
handlebars Prototype Pollution in handlebars High Risk 8.0 6 years ago 28 days ago
handlebars Prototype Pollution in handlebars Critical 9.8 4 years ago 28 days ago
handlebars Arbitrary Code Execution in handlebars High Risk 8.0 6 years ago 28 days ago
handlebars Arbitrary Code Execution in handlebars High Risk 7.3 6 years ago 28 days ago
handlebars Prototype Pollution in handlebars High Risk 7.3 7 years ago 28 days ago
handlebars Cross-Site Scripting in handlebars Medium Risk 6.1 7 years ago 28 days ago
com.github.jknack:handlebars-springmvc Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass High Risk 7.5 1 month ago 1 month ago
handlebars Regular Expression Denial of Service in Handlebars High Risk 7.5 4 years ago 3 months ago
com.github.jknack:handlebars handlebars.java FileTemplateLoader Path Traversal High Risk 7.5 3 months ago 3 months ago
kss-node-handlebars-builder Malicious code in kss-node-handlebars-builder (npm) Unknown 1 year ago 1 year ago
handlebars-inline-precompile Malicious code in handlebars-inline-precompile (npm) Unknown 1 year ago 1 year ago
modown-handlebars Malicious code in modown-handlebars (npm) Unknown 1 year ago 1 year ago
handlebars-formatter Malicious code in handlebars-formatter (npm) Unknown 1 year ago 1 year ago
handlebars-helper-attrs Malicious code in handlebars-helper-attrs (npm) Unknown 1 year ago 1 year ago
express-handlebars Insecure template handling in Express-handlebars High Risk 8.6 4 years ago 2 years ago
ember-handlebars Malicious code in ember-handlebars (npm) Unknown 4 years ago 2 years ago
handlebars Denial of Service in handlebars Medium Risk 6.0 6 years ago 6 years ago