Mjml is a focused email-template framework with a modest exposure footprint centered on its core markup-language processor and accompanying application. The observed vulnerability signal reflects the template-processing and file-system interaction inherent to the tooling, with recurring weaknesses in code injection and path-traversal conditions that are typical of systems that parse and execute user-supplied markup or resolve file references. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mjml over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25293CRITICAL mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute. | Mar 1, 2024 | 9.3 | 24 | NO | NO |
CVE-2020-12827HIGH MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document. | Jun 17, 2020 | 7.2 | 24 | NO | NO |
CVE-2025-67898MEDIUM MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for C | Dec 14, 2025 | 4.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mjml.
Media articles that mention a CVE ID that affects a product developed by Mjml — matched by CVE ID, not by vendor name.