handlebarsjs records
10 published records for vendor handlebarsjs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-754 Improper Check for Unusual or Exceptional Conditions1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2021-23369Proof of concept | Remote Code Execution (RCE)handlebarsjs · handlebars | Critical9.8 | — | 7.0% | Apr 12, 2021 |
40Plan | CVE-2021-23383Proof of concept | The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates comihandlebarsjs · handlebars · CWE-1321 | Critical9.8 | — | 4.5% | May 4, 2021 |
40Plan | CVE-2026-33937Proof of concept | Handlebars.js has JavaScript Injection via AST Type Confusionhandlebarsjs · handlebars · CWE-94 | Critical9.8 | — | 1.7% | Mar 27, 2026 |
33Monitor | CVE-2019-20920No exploit | Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution.handlebarsjs · handlebars · CWE-94 | High8.1 | — | 3.2% | Sep 30, 2020 |
32Monitor | CVE-2026-33938No exploit | Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-blockhandlebarsjs · handlebars · CWE-94 | High8.1 | — | 0.8% | Mar 27, 2026 |
32Monitor | CVE-2026-33940No exploit | Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partialhandlebarsjs · handlebars · CWE-94 | High8.1 | — | 0.8% | Mar 27, 2026 |
32Monitor | CVE-2026-33941No exploit | Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Optionshandlebarsjs · handlebars · CWE-79 | High8.2 | — | 0.2% | Mar 27, 2026 |
31Monitor | CVE-2019-20922No exploit | Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching.handlebarsjs · handlebars · CWE-400 | High7.5 | — | 3.7% | Sep 30, 2020 |
30Monitor | CVE-2026-33939No exploit | Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilationhandlebarsjs · handlebars · CWE-754 | High7.5 | — | 0.8% | Mar 27, 2026 |
18Monitor | CVE-2026-33916No exploit | Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injectionhandlebarsjs · handlebars · CWE-79 | Medium4.7 | — | 0.4% | Mar 27, 2026 |
- CVE-2021-2336941Plan
Remote Code Execution (RCE)
CriticalCVSS 9.8Proof of conceptEPSS 7%handlebarsjs · handlebarsApr 12, 2021
- CVE-2021-2338340Plan
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates comi
CriticalCVSS 9.8Proof of conceptEPSS 5%handlebarsjs · handlebarsMay 4, 2021
- CVE-2026-3393740Plan
Handlebars.js has JavaScript Injection via AST Type Confusion
CriticalCVSS 9.8Proof of conceptEPSS 2%handlebarsjs · handlebarsMar 27, 2026
- CVE-2019-2092033Monitor
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution.
HighCVSS 8.1No exploitEPSS 3%handlebarsjs · handlebarsSep 30, 2020
- CVE-2026-3393832Monitor
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
HighCVSS 8.1No exploitEPSS 1%handlebarsjs · handlebarsMar 27, 2026
- CVE-2026-3394032Monitor
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
HighCVSS 8.1No exploitEPSS 1%handlebarsjs · handlebarsMar 27, 2026
- CVE-2026-3394132Monitor
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
HighCVSS 8.2No exploitEPSS 0%handlebarsjs · handlebarsMar 27, 2026
- CVE-2019-2092231Monitor
Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching.
HighCVSS 7.5No exploitEPSS 4%handlebarsjs · handlebarsSep 30, 2020
- CVE-2026-3393930Monitor
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
HighCVSS 7.5No exploitEPSS 1%handlebarsjs · handlebarsMar 27, 2026
- CVE-2026-3391618Monitor
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
MediumCVSS 4.7No exploitEPSS 0%handlebarsjs · handlebarsMar 27, 2026