Known Vulnerabilities for Jinja2 by Pocoo
Listed below are 3 of the newest known vulnerabilities associated with "Jinja2" by "Pocoo".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100172 json | The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templa... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-91925 json | Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run ... | Not Provided | 2026-09-15 | 2026-09-24 |
| CVE-2026-77177 json | Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code executi... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-57170 json | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior... | Not Provided | 2026-08-26 | 2026-08-28 |
| CVE-2026-54757 json | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions befor... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-54654 json | datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-template... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-54621 json | datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description val... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-47752 json | Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-44845 json | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authen... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-44209 json | Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environm... | Not Provided | 2026-05-26 | 2026-07-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pocoo | Jinja2 | 2.9.6 | |||
| Application | Pocoo | Jinja2 | 2.9.5 | |||
| Application | Pocoo | Jinja2 | 2.9.4 | |||
| Application | Pocoo | Jinja2 | 2.9.3 | |||
| Application | Pocoo | Jinja2 | 2.9.2 | |||
| Application | Pocoo | Jinja2 | 2.9.1 | |||
| Application | Pocoo | Jinja2 | 2.9 | |||
| Application | Pocoo | Jinja2 | 2.8.1 | |||
| Application | Pocoo | Jinja2 | 2.8 | |||
| Application | Pocoo | Jinja2 | 2.7.3 | |||
| Application | Pocoo | Jinja2 | 2.7.2 | |||
| Application | Pocoo | Jinja2 | 2.7.1 | |||
| Application | Pocoo | Jinja2 | 2.7 | |||
| Application | Pocoo | Jinja2 | 2.6 | |||
| Application | Pocoo | Jinja2 | 2.5.5 | |||
| Application | Pocoo | Jinja2 | 2.5.4 | |||
| Application | Pocoo | Jinja2 | 2.5.3 | |||
| Application | Pocoo | Jinja2 | 2.5.2 | |||
| Application | Pocoo | Jinja2 | 2.5.1 | |||
| Application | Pocoo | Jinja2 | 2.5 |