Skip to content
Noroxi

palletsprojects records

27 published records for vendor palletsprojects.

All records

27 records
  • In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.

    HighCVSS 7.5Proof of conceptEPSS 56%

    palletsprojects · werkzeugJul 28, 2019

  • Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HT

    CriticalCVSS 9.8Proof of conceptEPSS 8%

    palletsprojects · werkzeugMay 24, 2022

  • In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.

    HighCVSS 8.6No exploitEPSS 4%

    palletsprojects · jinjaApr 6, 2019

  • In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.

    HighCVSS 8.6No exploitEPSS 4%

    palletsprojects · jinjaApr 8, 2019

  • The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large

    HighCVSS 7.5No exploitEPSS 4%

    palletsprojects · flaskAug 20, 2018

  • Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution

    HighCVSS 7.5WeaponizedEPSS 3%

    palletsprojects · werkzeugMay 6, 2024

  • Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same mac

    HighCVSS 7.5No exploitEPSS 2%

    palletsprojects · werkzeugAug 9, 2019

  • The Pallets Project Flask before 1.0 is affected by: unexpected memory usage.

    HighCVSS 7.5No exploitEPSS 2%

    palletsprojects · flaskJul 17, 2019

  • Werkzeug may allow high resource usage when parsing multipart form data with many fields

    HighCVSS 7.5No exploitEPSS 1%

    palletsprojects · werkzeugFeb 14, 2023

  • Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header

    HighCVSS 7.5Proof of conceptEPSS 1%

    palletsprojects · flaskMay 2, 2023

  • Werkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

    HighCVSS 7.5Proof of conceptEPSS 1%

    palletsprojects · werkzeugOct 25, 2023

  • CVE-2026-7246
    28Monitor

    [DISPUTED] Pallets Click contains a command injection via Unsanitized Filename "click.edit()"

    HighCVSS 7.2No exploitEPSS 1%

    palletsprojects · clickApr 30, 2026

  • Werkzeug possible resource exhaustion when parsing file data in forms

    MediumCVSS 6.9No exploitEPSS 1%

    palletsprojects · quartOct 25, 2024

  • Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11

    MediumCVSS 6.1No exploitEPSS 2%

    palletsprojects · werkzeugOct 23, 2017

  • Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.

    MediumCVSS 6.1No exploitEPSS 2%

    palletsprojects · werkzeugNov 18, 2020

  • Werkzeug safe_join not safe on Windows

    MediumCVSS 6.3No exploitEPSS 1%

    palletsprojects · werkzeugOct 25, 2024

  • Werkzeug safe_join() allows Windows special device names

    MediumCVSS 6.3Proof of conceptEPSS 1%

    palletsprojects · werkzeugFeb 21, 2026

  • Werkzeug safe_join() allows Windows special device names

    MediumCVSS 6.3No exploitEPSS 1%

    palletsprojects · werkzeugNov 28, 2025

  • Werkzeug safe_join() allows Windows special device names with compound extensions

    MediumCVSS 6.3No exploitEPSS 0%

    palletsprojects · werkzeugJan 8, 2026

  • Jinja vulnerable to Cross-Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 1%

    palletsprojects · jinjaJan 10, 2024

  • Regular Expression Denial of Service (ReDoS)

    MediumCVSS 5.3No exploitEPSS 4%

    palletsprojects · jinjaFeb 1, 2021

  • Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

    MediumCVSS 5.4Proof of conceptEPSS 1%

    palletsprojects · jinjaMay 6, 2024

  • Jinja has a sandbox breakout through indirect reference to format method

    MediumCVSS 5.4No exploitEPSS 1%

    palletsprojects · jinjaDec 23, 2024

  • Jinja sandbox breakout through attr filter selecting format method

    MediumCVSS 5.4No exploitEPSS 1%

    palletsprojects · jinjaMar 5, 2025

  • Jinja has a sandbox breakout through malicious filenames

    MediumCVSS 5.4No exploitEPSS 0%

    palletsprojects · jinjaDec 23, 2024