MJML records
2 published records for vendor mjml.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2024-25293Proof of concept | mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.mjml · mjml app · CWE-94 | Critical9.3 | — | 1.0% | Mar 1, 2024 |
29Monitor | CVE-2020-12827No exploit | MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.mjml · mjml · CWE-22 | High7.2 | — | 2.7% | Jun 17, 2020 |
- CVE-2024-2529337Monitor
mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.
CriticalCVSS 9.3Proof of conceptEPSS 1%mjml · mjml appMar 1, 2024
- CVE-2020-1282729Monitor
MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.
HighCVSS 7.2No exploitEPSS 3%mjml · mjmlJun 17, 2020