Nette is a lightweight, modestly represented PHP framework and templating engine (Latte) used for web application development, where its vulnerability footprint clusters around template and input-handling weaknesses. The recurring exposure centers on code injection, cross-site scripting, injection flaws, and authorization bypasses that reflect the framework's role in processing user-supplied content and controlling access to application features. Live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nette over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15227CRITICAL Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leadi | Oct 1, 2020 | 9.8 | 62 | NO | YES |
CVE-2021-23803CRITICAL This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disa | Dec 17, 2021 | 9.8 | 28 | NO | NO |
CVE-2022-21648MEDIUM Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists | Jan 4, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nette.
Media articles that mention a CVE ID that affects a product developed by Nette — matched by CVE ID, not by vendor name.