CVE-2017-1000188: Ejs
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection
Affected products
- Ejs Ejs: before 2.5.5 (fixed in 2.5.5)
Published 2017-11-17. Last modified 2026-06-17.