Palletsprojects / Jinja
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-27516 | Jinja sandbox breakout through attr filter selecting format method | MEDIUM | 5.4 | Mar 5, 2025 |
| CVE-2024-56326 | Jinja has a sandbox breakout through indirect reference to format method | MEDIUM | 5.4 | Dec 23, 2024 |
| CVE-2024-56201 | Jinja has a sandbox breakout through malicious filenames | MEDIUM | 5.4 | Dec 23, 2024 |
| CVE-2024-34064 | Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter | MEDIUM | 5.4 | May 6, 2024 |
| CVE-2024-22195 | Jinja vulnerable to Cross-Site Scripting (XSS) | MEDIUM | 6.1 | Jan 11, 2024 |
| CVE-2020-28493 | Regular Expression Denial of Service (ReDoS) | MEDIUM | 6.9 | Feb 1, 2021 |
| CVE-2016-10745 | python-jinja2: Sandbox escape due to information disclosure via str.format | HIGH | 7.7 | Apr 8, 2019 |
| CVE-2019-10906 | python-jinja2: str.format_map allows sandbox escape | HIGH | 7.7 | Apr 6, 2019 |
Showing 1 to 8 of 8 CVEs