Vulnerabilities > EJS > EJS > 2.5.3

DATE CVE VULNERABILITY TITLE RISK
2017-11-17 CVE-2017-1000189 Improper Input Validation vulnerability in EJS
nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderFile()
network
low complexity
ejs CWE-20
5.0
2017-11-17 CVE-2017-1000188 Cross-site Scripting vulnerability in EJS
nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection
network
ejs CWE-79
4.3