VendorsHubSpotjinjavaany version
Vulnerabilities

HubSpot Jinjava any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2025-59340
jinjava Sandbox Bypass via JavaType-Based Deserialization
Published 2025-09-17 · Analyzed
10.0EPSS 0.021
CVE-2026-25526
JinJava Bypass through ForTag leads to Arbitrary Java Execution
Published 2026-02-04 · Analyzed
9.8EPSS 0.009
CVE-2020-12668
Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.
Published 2021-02-19 · Modified
6.8EPSS 0.018
CVE-2018-18893
Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java.
Published 2019-01-03 · Modified
5.3EPSS 0.018