palletsprojects
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 27 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 23, 2017 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Pallets Click contains a command injection via Unsanitized Filename "click.edit()"
Flask session does not add `Vary: Cookie` header when accessed in some ways
Werkzeug safe_join() allows Windows special device names
Werkzeug safe_join() allows Windows special device names with compound extensions
Werkzeug safe_join() allows Windows special device names
Jinja sandbox breakout through attr filter selecting format method
Jinja has a sandbox breakout through indirect reference to format method
Jinja has a sandbox breakout through malicious filenames
Werkzeug possible resource exhaustion when parsing file data in forms
Werkzeug safe_join not safe on Windows
Monitor palletsprojects in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.