jinja2 has 5 CVEs on record between 2024 and 2025. The median CVSS is 7.3 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- jinja2 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2024-56201High· 8.8Jinja has a sandbox breakout through malicious filenames48CVE-2024-56326High· 7.8Jinja has a sandbox breakout through indirect reference to format method43CVE-2024-34064Medium· 5.4Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter42CVE-2025-27516Medium· 7.3Jinja2 vulnerable to sandbox breakout through attr filter selecting format method40CVE-2024-22195Medium· 5.4Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter30
jinja2 vulnerabilities
CVEs affecting jinja2, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2025-27516Medium· 7.3Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
▾ Sunlitjinja2 · jinja2EPSS 0.50%via OSV
CVE-2024-56326High· 7.8Jinja has a sandbox breakout through indirect reference to format method
Jinja has a sandbox breakout through indirect reference to format method
▾ Twilightjinja2 · jinja2EPSS 0.52%via OSV
CVE-2024-56201High· 8.8Jinja has a sandbox breakout through malicious filenames
Jinja has a sandbox breakout through malicious filenames
▾ Twilightjinja2 · jinja2EPSS 0.31%via OSV
CVE-2024-34064Medium· 5.4PoCJinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
▾ Twilightjinja2 · jinja2EPSS 0.98%via OSV
CVE-2024-22195Medium· 5.4Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
▾ Sunlitjinja2 · jinja2EPSS 0.89%via OSV