Handlebars.js ProjectCVEs & Vulnerabilities
2 CVEs affecting Handlebars.js Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
handlebars.js 44
CVE-2019-19919CRITICAL
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
21 Dec 2019
9.8
CVSS
CVE-2015-8861MEDIUM
The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.
23 Jan 2017
6.1
CVSS
← PrevPage 1 / 1Next →