Handlebars.js Project maintains a focused templating library widely embedded in web applications, where its vulnerability profile centers on input-handling risks inherent to template processing. The durable signal reflects recurrent weakness classes including cross-site scripting through improper neutralization of user input and prototype pollution via uncontrolled object-attribute modification, both endemic to JavaScript template engines. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Handlebars.Js Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19919CRITICAL Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ propert | Dec 20, 2019 | 9.8 | 34 | NO | NO |
CVE-2015-8861MEDIUM The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted. | Jan 23, 2017 | 6.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Handlebars.Js Project.
Media articles that mention a CVE ID that affects a product developed by Handlebars.Js Project — matched by CVE ID, not by vendor name.