Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Palletsprojects

First CVE: Oct 23, 2017Active for: 9 yearsTotal CVEs: 27
49.0
VTI Score
High

Palletsprojects maintains a focused but widely embedded collection of Python web frameworks and utilities—including Flask, Werkzeug, Jinja, Click, and Quart—that are fundamental dependencies across countless web applications and development toolchains. Despite the modestly sized product footprint, the vendor's prominence in the Python ecosystem means that vulnerabilities propagate broadly through downstream applications, and the disclosures have acquired public exploit code at a moderate tendency. The recurring weakness classes center on web-application layers: cross-site scripting and input-neutralization flaws in templating and request handling, resource-consumption issues, and Windows path-handling edge cases that reflect the parser and I/O demands of a widely ported framework suite. Defenders should treat Palletsprojects releases as supply-chain events and audit downstream consumers; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Palletsprojects over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 23, 2017
8 years ago
Most Recent CVE
Apr 30, 2026
85 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-14322HIGH
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
Jul 28, 20197.573NOYES
CVE-2024-34069HIGH
Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some ci
May 6, 20247.534NOYES
CVE-2022-29361CRITICAL
Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests includ
May 25, 20229.834NONO
CVE-2026-7246HIGH
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileg
Apr 30, 20267.232NONO
CVE-2016-10745HIGH
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
Apr 8, 20198.629NONO
CVE-2019-10906HIGH
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
Apr 7, 20198.629NONO
CVE-2025-27516HIGH
Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the c
Mar 5, 20258.827NONO
CVE-2024-56201HIGH
Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls both the content and filename o
Dec 23, 20248.827NONO
CVE-2018-1000656HIGH
The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading
Aug 20, 20187.526NONO
CVE-2024-56326HIGH
Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the conte
Dec 23, 20247.825NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
37%
56%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (14.8%)
Network22 (81.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.7%)
Attack Complexity
Low25 (92.6%)
High2 (7.4%)
Unknown0 (0.0%)
User Interaction
None19 (70.4%)
Unknown0 (0.0%)
Required8 (29.6%)
Privileges Required
Low3 (11.1%)
High1 (3.7%)
None23 (85.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.7% of CVEs· 98th percentile
Nuclei
1 CVE
3.7% of CVEs· 95th percentile
ExploitDB
1 CVE
3.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Palletsprojects.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Palletsprojects — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Palletsprojects's Products

View all 5 CNAs →

Top CWEs