Express Handlebars Project maintains a templating engine widely embedded in Node.js web applications, and its vulnerability profile centers on the single express-handlebars product with durable exposure patterns around sensitive-information disclosure and code-injection risks inherent to template-processing systems. These weakness classes reflect the intersection of dynamic template rendering and the challenge of safely handling user-controlled input in contexts where expression evaluation occurs. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Express Handlebars Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32820HIGH Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the Express render API. More speci | May 14, 2021 | 8.6 | 47 | NO | YES |
CVE-2021-32817MEDIUM express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration options through the Express render API. More specifically, the | May 14, 2021 | 6.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Express Handlebars Project.
Media articles that mention a CVE ID that affects a product developed by Express Handlebars Project — matched by CVE ID, not by vendor name.