Handlebars.js
Handlebarsjs · 2 CVEs
CVE-2019-19919
CRITICAL
nodejs-handlebars: prototype pollution leading to remote code execution via crafted payloads
Dec 20, 2019
CVE-2015-8861
MEDIUM
The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks b…
Jan 23, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2019-19919 | nodejs-handlebars: prototype pollution leading to remote code execution via crafted payloads | CRITICAL | 7.07% | Dec 20, 2019 |
| CVE-2015-8861 | The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribut… | MEDIUM | 2.61% | Jan 23, 2017 |
Showing 1 to 2 of 2 CVEs