Skip to main content

Vendor/product archive

palletsprojects / jinja CVEs

Beta · best-effort

8 CVEs tagged to palletsprojects / jinja0 Critical, 2 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2025-27516

Published Mar 5, 2025

Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2024-56326

Published Dec 23, 2024

Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the cont…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56201

Published Dec 23, 2024

Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls both the content and filename…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22195

Published Jan 11, 2024

Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1