Ejs is a templating engine for Node.js that generates dynamic HTML, and its vulnerability profile centers on the single Ejs product with a durable signal around template-injection and input-handling weaknesses. The recurring vulnerability classes—improper input validation, code injection, cross-site scripting, and downstream injection—reflect the parser and code-generation demands inherent to a template processor that interprets user-supplied content. Current severity, exploitation, and disclosure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ejs over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29078CRITICAL The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an inte | Apr 25, 2022 | 9.8 | 61 | NO | YES |
CVE-2023-29827CRITICAL ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDe | May 4, 2023 | 9.8 | 44 | NO | YES |
CVE-2017-1000228CRITICAL nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function | Nov 17, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-1000189HIGH nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderFile() | Nov 17, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-1000188MEDIUM nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection | Nov 17, 2017 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ejs.
Media articles that mention a CVE ID that affects a product developed by Ejs — matched by CVE ID, not by vendor name.