Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    3
    Critical Level Threats
    1
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-29827

    ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input.

    Last Modified: Dec 03, 2025
    Published: May 04, 2023

    CVE-2022-29078

    ejs: server-side template injection in outputFunctionName

    Last Modified: Nov 21, 2024
    Published: Apr 25, 2022

    CVE-2017-1000228

    nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function

    Last Modified: Apr 20, 2025
    Published: Nov 17, 2017

    CVE-2017-1000189

    nodejs-ejs: Denial of Service via renderFile() by overriding localNames

    Last Modified: Apr 20, 2025
    Published: Dec 06, 2016

    CVE-2017-1000188

    nodejs-ejs: Cross-site scripting via ejs.renderFile()

    Last Modified: Apr 20, 2025
    Published: Dec 06, 2016
    Items Per Page
    Ejs Vulnerabilities & Security CVEs | CVE-DB