VYPR

Nunjucks

by Mozilla Corporation

npm: nunjucks

Source repositories

CVEs (2)

  • CVE-2016-10547MedMay 31, 2018
    risk 0.40cvss 6.1epss 0.01

    Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape mode. In autoescape mode, all template vars should automatically be escaped. By using an array for the keys, such as…

  • CVE-2023-2142MedNov 26, 2024
    risk 0.33cvss 6.1epss 0.00

    In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads…