mustache
Releases39
Frequency2 months 3 weeks
Last Release
Logic-less {{mustache}} templates with JavaScript
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| >= 2.0.0, < 2.14.1 | 8.8 HIGH | 6.5 MEDIUM | ||
Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1. | ||||
| < 2.2.1 | — | 4.3 MEDIUM | ||
mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted. | ||||