liquidjs has 3 CVEs on record. 3 were published in the last 90 days. The median CVSS is 7.5 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-69222High· 7.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript41CVE-2026-61556HighLiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript41CVE-2026-55575HighLiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce41
liquidjs vulnerabilities
CVEs affecting liquidjs, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-69222High· 7.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, the join filter in src/filters/array.ts computes complexity from array.length and separator length instead of the total string length p…
CVE-2026-61556HighLiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 until 10.27.1, the strip_html filter in src/filters/html.ts can enter an infinite loop when an input string contains <, includes at least on…
CVE-2026-55575HighLiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce