Known Vulnerabilities for products from Ejs
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Ejs".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-29827 json | ** DISPUTED ** ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injectio... | 9.8 - CRITICAL | 2023-05-04 | 2023-11-07 |
| CVE-2022-29078 json | The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view ... | 9.8 - CRITICAL | 2022-04-25 | 2023-08-08 |
| CVE-2017-1000228 json | nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() ... | Not Provided | 2017-11-17 | 2025-04-20 |
| CVE-2017-1000189 json | nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderFile() | Not Provided | 2017-11-17 | 2025-04-20 |
| CVE-2017-1000188 json | nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injecti... | Not Provided | 2017-11-17 | 2025-04-20 |
Known software with vulnerabilities from Ejs
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Ejs | Ejs | 2.0.1 |