Xiandafu's vulnerability footprint centers on Beetl, a template engine product, with the durable signal focused on code-injection risks arising from improper control of code generation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xiandafu over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-22533CRITICAL Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the Defa | Feb 2, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xiandafu.
Media articles that mention a CVE ID that affects a product developed by Xiandafu — matched by CVE ID, not by vendor name.