Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jinjava CRITICAL 9.8
CVE-2026-25526

JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJav…

Fix: 2.7.6 / 2.8.3+
Fix from $2,300 2026-02-04
Jinjava CRITICAL 10.0
CVE-2025-59340

jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.8.1, by using mapper.getTypeF…

Fix: 2.8.1+
Fix from $2,300 2025-09-17
Hubspot MEDIUM 5.4
CVE-2024-5879

The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attr…

Fix: 11.1.34+
Fix from $1,600 2024-08-30
Hubspot HIGH 8.8
CVE-2022-1239

The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_po…

Fix: 8.8.15+
Fix from $1,950 2022-05-02
Jinjava MEDIUM 6.5
CVE-2020-12668

Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse o…

Fix: 2.5.4+
Fix from $1,600 2021-02-19
Jinjava MEDIUM 5.3
CVE-2018-18893

Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java.

Fix: 2.4.6+
Fix from $1,600 2019-01-03
Hubl Server HIGH 8.1
CVE-2017-16035

The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.…

Fix: after 1.1.5
Fix from $1,950 2018-06-04