Thymeleaf

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 5
    Known Exploited: 0
    4
    Critical Level Threats
    1
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-41901

    Thymeleaf: Improper recognition of unauthorized syntax patterns in sandboxed Thymeleaf expressions

    Last Modified: May 13, 2026
    Published: May 12, 2026

    CVE-2026-40478

    Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf

    Last Modified: Apr 24, 2026
    Published: Apr 17, 2026

    CVE-2026-40477

    Improper restriction of the scope of accessible objects in Thymeleaf expressions

    Last Modified: Apr 24, 2026
    Published: Apr 17, 2026

    CVE-2023-38286

    Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.

    Last Modified: Nov 21, 2024
    Published: Jul 14, 2023

    CVE-2021-43466

    In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.

    Last Modified: Nov 21, 2024
    Published: Nov 09, 2021
    Items Per Page