Vulnerabilities (CVE)

Filtered by vendor Handlebars.js Project Subscribe
Filtered by product Handlebars.js
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-8861 1 Handlebars.js Project 1 Handlebars.js 2020-04-22 4.3 MEDIUM 6.1 MEDIUM
The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.