Products: 2
    Vulnerabilities: 3
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-67898

    MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

    Last Modified: Apr 15, 2026
    Published: Dec 14, 2025

    CVE-2024-25293

    mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.

    Last Modified: May 13, 2025
    Published: Mar 01, 2024

    CVE-2020-12827

    MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.

    Last Modified: Nov 21, 2024
    Published: Jun 17, 2020
    Items Per Page
    Mjml Vulnerabilities & Security CVEs | CVE-DB