Skip to content
Noroxi

thymeleaf records

4 published records for vendor thymeleaf.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

4 records
  • In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code executio

    CriticalCVSS 9.8No exploitEPSS 4%

    thymeleaf · thymeleafNov 9, 2021

  • Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf

    CriticalCVSS 9.0No exploitEPSS 1%

    thymeleaf · thymeleafApr 17, 2026

  • Improper restriction of the scope of accessible objects in Thymeleaf expressions

    CriticalCVSS 9.0Proof of conceptEPSS 1%

    thymeleaf · thymeleafApr 17, 2026

  • Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypas

    HighCVSS 7.5No exploitEPSS 1%

    thymeleaf · thymeleafJul 14, 2023