Known vulnerabilities in handlebars
Vendor:
wycats
Software:
handlebars
Software CPE:
cpe:2.3:a:wycats:handlebars:*:*:*:*:*:npm:*:*
Website:
https://www.npmjs.com/~wycats
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
4.7.9
4.7.8
4.7.7
4.7.6
4.7.5
4.7.4
4.7.3
4.7.2
4.7.1
4.7.0
4.6.0
3.0.8
1.0.0
4.5.3
4.5.2
4.5.1
4.5.0
4.4.5
4.4.4
4.4.3
4.4.2
4.2.2
4.3.5
4.4.1
4.4.0
4.3.4
4.3.3
4.3.2
4.3.1
4.3.0
4.2.1
4.2.0
3.0.7
4.0.14
4.1.2
4.1.1
4.0.13
4.1.0
3.0.6
3.0.5
3.0.4
4.0.12
4.0.11
4.0.10
4.0.9
4.0.8
4.0.7
4.0.6
4.0.5
4.0.4
4.0.3
4.0.2
4.0.1
4.0.0
3.0.3
3.0.2
3.0.1
3.0.0
2.0.0
1.3.0
1.2.1
1.2.0
1.1.2
1.1.1
1.1.0
1.0.12
1.0.11
1.0.10
1.0.9
1.0.8
1.0.7
1.0.6
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU23982 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2019-20922 |
CWE-835 | Medium | 4.4.5 | 06.01.2020 |
SB2019103021 SB2021070402 SB2023020928 and 4 more |
||
| #VU23942 - Improper Control of Generation of Code ('Code Injection') |
CWE-94 | Medium | - | 06.01.2020 |
SB2019091624 |
||
| #VU23941 - Improper Control of Generation of Code ('Code Injection') |
CWE-94 | Medium | 4.3.0 | 06.01.2020 |
SB2019091622 |
||
| #VU23932 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Low | 4.5.3 | 05.01.2020 |
SB2019111922 |
||
| #VU23930 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Low | 4.5.2 | 05.01.2020 |
SB2019111817 |
||
| #VU23929 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2019-20920 |
CWE-79 | Low | 4.5.3 | 05.01.2020 |
SB2019111922 SB2021070402 SB2023020928 and 4 more |