VendorsPalletsprojectsjinjaall versions
Vulnerabilities

Palletsprojects Jinja

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2025-27516
Jinja sandbox breakout through attr filter selecting format method
Published 2025-03-05 · Modified
8.8EPSS 0.005
CVE-2024-56201
Jinja has a sandbox breakout through malicious filenames
Published 2024-12-23 · Analyzed
8.8EPSS 0.003
CVE-2019-10906
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
Published 2019-04-06 · Modified
8.6EPSS 0.036
CVE-2016-10745
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
Published 2019-04-08 · Modified
8.6EPSS 0.035
CVE-2024-56326
Jinja has a sandbox breakout through indirect reference to format method
Published 2024-12-23 · Modified
7.8EPSS 0.005
CVE-2024-22195
Jinja vulnerable to Cross-Site Scripting (XSS)
Published 2024-01-11 · Modified
6.1EPSS 0.009
CVE-2024-34064
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Published 2024-05-06 · Modified
5.4EPSS 0.010
CVE-2020-28493
Regular Expression Denial of Service (ReDoS)
Published 2021-02-01 · Modified
5.3EPSS 0.035