Handlebarsjs
2 CVEs tracked since 2020. Since Sep 2020, none of them reached CISA KEV.
Handlebarsjs CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-09 | 2 | 0 |
Products
The products that kept showing up in Handlebarsjs's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 10 most recently published vulnerabilities affecting Handlebarsjs.
- CVE-2026-33941Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options8.2
- CVE-2026-33940Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial8.1
- CVE-2026-33939Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation7.5
- CVE-2026-33938Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block8.1
- CVE-2026-33937Handlebars.js has JavaScript Injection via AST Type Confusion9.8
- CVE-2026-33916Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection4.7
- CVE-2021-23383Prototype Pollution5.6
- CVE-2021-23369Remote Code Execution (RCE)5.6
- CVE-2019-20920Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute a...8.1
- CVE-2019-20922Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may all...7.5
The record
- Peak rank
- #156 in Sep 2020
- Busiest month shown
- Sep 2020, 2 CVEs
- Months with a KEV entry
- 0 since Sep 2020
- Monthly snapshots
- 1 since 2020