Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-67898 1 Mjml 1 Mjml 2025-12-15 4.5 Medium
MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.
CVE-2024-25293 1 Mjml 1 Mjml App 2025-05-13 9.3 Critical
mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.
CVE-2020-12827 1 Mjml 1 Mjml 2024-11-21 7.2 High
MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.