Vulnerabilities (CVE)

Filtered by vendor Handlebars.js Project Subscribe
Filtered by product Handlebars.js
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-19919 2 Handlebars.js Project, Tenable 2 Handlebars.js, Tenable.sc 2023-12-10 7.5 HIGH 9.8 CRITICAL
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
CVE-2015-8861 1 Handlebars.js Project 1 Handlebars.js 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.