CVE-2017-1000188: Ejs

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection

Affected products

  • Ejs Ejs: before 2.5.5 (fixed in 2.5.5)

Published 2017-11-17. Last modified 2026-06-17.