palletsprojects records
27 published records for vendor palletsprojects.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.7%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-400 Uncontrolled Resource Consumption3
- CWE-67 Improper Handling of Windows Device Names3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-20 Improper Input Validation2
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2019-14322Proof of concept | In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.palletsprojects · werkzeug · CWE-22 | High7.5 | — | 55.8% | Jul 28, 2019 |
41Plan | CVE-2022-29361Proof of concept | Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTpalletsprojects · werkzeug · CWE-444 | Critical9.8 | — | 8.1% | May 24, 2022 |
35Monitor | CVE-2019-10906No exploit | In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.palletsprojects · jinja | High8.6 | — | 3.6% | Apr 6, 2019 |
35Monitor | CVE-2016-10745No exploit | In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.palletsprojects · jinja · CWE-134 | High8.6 | — | 3.5% | Apr 8, 2019 |
31Monitor | CVE-2018-1000656No exploit | The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Largepalletsprojects · flask · CWE-20 | High7.5 | — | 3.9% | Aug 20, 2018 |
31Monitor | CVE-2024-34069Weaponized | Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command executionpalletsprojects · werkzeug · CWE-352 | High7.5 | — | 3.4% | May 6, 2024 |
31Monitor | CVE-2019-14806No exploit | Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same macpalletsprojects · werkzeug · CWE-331 | High7.5 | — | 2.3% | Aug 9, 2019 |
31Monitor | CVE-2019-1010083No exploit | The Pallets Project Flask before 1.0 is affected by: unexpected memory usage.palletsprojects · flask | High7.5 | — | 1.9% | Jul 17, 2019 |
30Monitor | CVE-2023-25577No exploit | Werkzeug may allow high resource usage when parsing multipart form data with many fieldspalletsprojects · werkzeug · CWE-770 | High7.5 | — | 1.4% | Feb 14, 2023 |
30Monitor | CVE-2023-30861Proof of concept | Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie headerpalletsprojects · flask · CWE-539 | High7.5 | — | 1.3% | May 2, 2023 |
30Monitor | CVE-2023-46136Proof of concept | Werkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginningpalletsprojects · werkzeug · CWE-400 | High7.5 | — | 1.1% | Oct 25, 2023 |
28Monitor | CVE-2026-7246No exploit | [DISPUTED] Pallets Click contains a command injection via Unsanitized Filename "click.edit()"palletsprojects · click · CWE-77 | High7.2 | — | 0.9% | Apr 30, 2026 |
27Monitor | CVE-2024-49767No exploit | Werkzeug possible resource exhaustion when parsing file data in formspalletsprojects · quart · CWE-400 | Medium6.9 | — | 1.1% | Oct 25, 2024 |
25Monitor | CVE-2016-10516No exploit | Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 palletsprojects · werkzeug · CWE-79 | Medium6.1 | — | 2.0% | Oct 23, 2017 |
25Monitor | CVE-2020-28724No exploit | Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.palletsprojects · werkzeug · CWE-601 | Medium6.1 | — | 1.7% | Nov 18, 2020 |
25Monitor | CVE-2024-49766No exploit | Werkzeug safe_join not safe on Windowspalletsprojects · werkzeug · CWE-22 | Medium6.3 | — | 0.8% | Oct 25, 2024 |
25Monitor | CVE-2026-27199Proof of concept | Werkzeug safe_join() allows Windows special device namespalletsprojects · werkzeug · CWE-67 | Medium6.3 | — | 0.5% | Feb 21, 2026 |
25Monitor | CVE-2025-66221No exploit | Werkzeug safe_join() allows Windows special device namespalletsprojects · werkzeug · CWE-67 | Medium6.3 | — | 0.5% | Nov 28, 2025 |
25Monitor | CVE-2026-21860No exploit | Werkzeug safe_join() allows Windows special device names with compound extensionspalletsprojects · werkzeug · CWE-67 | Medium6.3 | — | 0.5% | Jan 8, 2026 |
24Monitor | CVE-2024-22195No exploit | Jinja vulnerable to Cross-Site Scripting (XSS)palletsprojects · jinja · CWE-79 | Medium6.1 | — | 0.9% | Jan 10, 2024 |
22Monitor | CVE-2020-28493No exploit | Regular Expression Denial of Service (ReDoS)palletsprojects · jinja · CWE-400 | Medium5.3 | — | 3.5% | Feb 1, 2021 |
21Monitor | CVE-2024-34064Proof of concept | Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterpalletsprojects · jinja · CWE-79 | Medium5.4 | — | 1.0% | May 6, 2024 |
21Monitor | CVE-2024-56326No exploit | Jinja has a sandbox breakout through indirect reference to format methodpalletsprojects · jinja · CWE-693 | Medium5.4 | — | 0.5% | Dec 23, 2024 |
21Monitor | CVE-2025-27516No exploit | Jinja sandbox breakout through attr filter selecting format methodpalletsprojects · jinja · CWE-1336 | Medium5.4 | — | 0.5% | Mar 5, 2025 |
21Monitor | CVE-2024-56201No exploit | Jinja has a sandbox breakout through malicious filenamespalletsprojects · jinja · CWE-150 | Medium5.4 | — | 0.3% | Dec 23, 2024 |
- CVE-2019-1432247Plan
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
HighCVSS 7.5Proof of conceptEPSS 56%palletsprojects · werkzeugJul 28, 2019
- CVE-2022-2936141Plan
Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HT
CriticalCVSS 9.8Proof of conceptEPSS 8%palletsprojects · werkzeugMay 24, 2022
- CVE-2019-1090635Monitor
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
HighCVSS 8.6No exploitEPSS 4%palletsprojects · jinjaApr 6, 2019
- CVE-2016-1074535Monitor
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
HighCVSS 8.6No exploitEPSS 4%palletsprojects · jinjaApr 8, 2019
- CVE-2018-100065631Monitor
The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large
HighCVSS 7.5No exploitEPSS 4%palletsprojects · flaskAug 20, 2018
- CVE-2024-3406931Monitor
Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
HighCVSS 7.5WeaponizedEPSS 3%palletsprojects · werkzeugMay 6, 2024
- CVE-2019-1480631Monitor
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same mac
HighCVSS 7.5No exploitEPSS 2%palletsprojects · werkzeugAug 9, 2019
- CVE-2019-101008331Monitor
The Pallets Project Flask before 1.0 is affected by: unexpected memory usage.
HighCVSS 7.5No exploitEPSS 2%palletsprojects · flaskJul 17, 2019
- CVE-2023-2557730Monitor
Werkzeug may allow high resource usage when parsing multipart form data with many fields
HighCVSS 7.5No exploitEPSS 1%palletsprojects · werkzeugFeb 14, 2023
- CVE-2023-3086130Monitor
Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
HighCVSS 7.5Proof of conceptEPSS 1%palletsprojects · flaskMay 2, 2023
- CVE-2023-4613630Monitor
Werkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
HighCVSS 7.5Proof of conceptEPSS 1%palletsprojects · werkzeugOct 25, 2023
- CVE-2026-724628Monitor
[DISPUTED] Pallets Click contains a command injection via Unsanitized Filename "click.edit()"
HighCVSS 7.2No exploitEPSS 1%palletsprojects · clickApr 30, 2026
- CVE-2024-4976727Monitor
Werkzeug possible resource exhaustion when parsing file data in forms
MediumCVSS 6.9No exploitEPSS 1%palletsprojects · quartOct 25, 2024
- CVE-2016-1051625Monitor
Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11
MediumCVSS 6.1No exploitEPSS 2%palletsprojects · werkzeugOct 23, 2017
- CVE-2020-2872425Monitor
Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
MediumCVSS 6.1No exploitEPSS 2%palletsprojects · werkzeugNov 18, 2020
- CVE-2024-4976625Monitor
Werkzeug safe_join not safe on Windows
MediumCVSS 6.3No exploitEPSS 1%palletsprojects · werkzeugOct 25, 2024
- CVE-2026-2719925Monitor
Werkzeug safe_join() allows Windows special device names
MediumCVSS 6.3Proof of conceptEPSS 1%palletsprojects · werkzeugFeb 21, 2026
- CVE-2025-6622125Monitor
Werkzeug safe_join() allows Windows special device names
MediumCVSS 6.3No exploitEPSS 1%palletsprojects · werkzeugNov 28, 2025
- CVE-2026-2186025Monitor
Werkzeug safe_join() allows Windows special device names with compound extensions
MediumCVSS 6.3No exploitEPSS 0%palletsprojects · werkzeugJan 8, 2026
- CVE-2024-2219524Monitor
Jinja vulnerable to Cross-Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 1%palletsprojects · jinjaJan 10, 2024
- CVE-2020-2849322Monitor
Regular Expression Denial of Service (ReDoS)
MediumCVSS 5.3No exploitEPSS 4%palletsprojects · jinjaFeb 1, 2021
- CVE-2024-3406421Monitor
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
MediumCVSS 5.4Proof of conceptEPSS 1%palletsprojects · jinjaMay 6, 2024
- CVE-2024-5632621Monitor
Jinja has a sandbox breakout through indirect reference to format method
MediumCVSS 5.4No exploitEPSS 1%palletsprojects · jinjaDec 23, 2024
- CVE-2025-2751621Monitor
Jinja sandbox breakout through attr filter selecting format method
MediumCVSS 5.4No exploitEPSS 1%palletsprojects · jinjaMar 5, 2025
- CVE-2024-5620121Monitor
Jinja has a sandbox breakout through malicious filenames
MediumCVSS 5.4No exploitEPSS 0%palletsprojects · jinjaDec 23, 2024