Palletsprojects

    Dashboard / Vendors

    Products: 5
    Vulnerabilities: 27
    Known Exploited: 0
    1
    Critical Level Threats
    15
    High Level Threats
    10
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-7246

    [DISPUTED] Pallets Click contains a command injection via Unsanitized Filename "click.edit()"

    Last Modified: Aug 18, 2026
    Published: Apr 30, 2026

    CVE-2026-27205

    Flask session does not add `Vary: Cookie` header when accessed in some ways

    Last Modified: Apr 17, 2026
    Published: Feb 21, 2026

    CVE-2026-27199

    Werkzeug safe_join() allows Windows special device names

    Last Modified: Apr 17, 2026
    Published: Feb 21, 2026

    CVE-2026-21860

    Werkzeug safe_join() allows Windows special device names with compound extensions

    Last Modified: Apr 18, 2026
    Published: Jan 08, 2026

    CVE-2025-66221

    Werkzeug safe_join() allows Windows special device names

    Last Modified: Dec 03, 2025
    Published: Nov 29, 2025
    Items Per Page
    Palletsprojects Vulnerabilities & Security CVEs | CVE-DB