pallets jinja

5 known vulnerabilities in pallets jinja, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2025-27516 CVSS 5.4 medium Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr…
  • CVE-2024-56326 CVSS 5.4 medium Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format…
  • CVE-2024-56201 CVSS 5.4 medium Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker…
  • CVE-2024-34064 CVSS 5.4 medium Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute…
  • CVE-2024-22195 CVSS 6.1 medium Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible…