Skip to content
Noroxi

handlebarsjs records

10 published records for vendor handlebarsjs.

All records

10 records
  • Remote Code Execution (RCE)

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    handlebarsjs · handlebarsApr 12, 2021

  • The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates comi

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    handlebarsjs · handlebarsMay 4, 2021

  • Handlebars.js has JavaScript Injection via AST Type Confusion

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    handlebarsjs · handlebarsMar 27, 2026

  • Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution.

    HighCVSS 8.1No exploitEPSS 3%

    handlebarsjs · handlebarsSep 30, 2020

  • Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block

    HighCVSS 8.1No exploitEPSS 1%

    handlebarsjs · handlebarsMar 27, 2026

  • Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial

    HighCVSS 8.1No exploitEPSS 1%

    handlebarsjs · handlebarsMar 27, 2026

  • Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options

    HighCVSS 8.2No exploitEPSS 0%

    handlebarsjs · handlebarsMar 27, 2026

  • Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching.

    HighCVSS 7.5No exploitEPSS 4%

    handlebarsjs · handlebarsSep 30, 2020

  • Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation

    HighCVSS 7.5No exploitEPSS 1%

    handlebarsjs · handlebarsMar 27, 2026

  • Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection

    MediumCVSS 4.7No exploitEPSS 0%

    handlebarsjs · handlebarsMar 27, 2026