Httl Project maintains a narrowly scoped templating engine that, despite limited disclosure volume, addresses a structural position in web application rendering where input handling defects can propagate broadly. The vendor's observed vulnerability pattern centers on improper input validation within the template processing pipeline, a class of weakness that reflects the parsing and expression-evaluation demands inherent to template-language implementations. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Httl Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19531CRITICAL HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses java.beans.XMLEncoder unsafely when configured without an | Nov 26, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-19530CRITICAL HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses XStream unsafely when configured with an xml.codec=httl.s | Nov 26, 2018 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Httl Project.
Media articles that mention a CVE ID that affects a product developed by Httl Project — matched by CVE ID, not by vendor name.