Skip to content

Known CVE

Embedded JavaScript(EJS) 3.1.6 - Template Injection

ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter.

CVE-2023-29827

Critical2023CVSS 9.8CWE-74

cve2023 · ssti · rce · ejs · oast · node.js · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website