Jstachio is a Java-based templating library with a narrow, focused product scope centered on its core templating engine. The observed vulnerability signal reflects application-layer input-handling concerns, specifically cross-site scripting risks arising from template generation and neutralization patterns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jstachio Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33962MEDIUM JStachio is a type-safe Java Mustache templating engine. Prior to version 1.0.1, JStachio fails to escape single quotes `'` in HTML, allowing an attacker to inject malicious code. | May 30, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jstachio Project.
Media articles that mention a CVE ID that affects a product developed by Jstachio Project — matched by CVE ID, not by vendor name.