Ejs vendor intelligence
Ejs Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Ejs products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 4
- Known exploited vulnerabilities affecting Ejs products
- In CISA KEV
- 1
- Records also listed in the official catalog
- Beyond CISA KEV
- 3
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 1
- Ejs KEV with sensor-observed exploitation activity
The catalog gap matters for Ejs exposure
Three of the four exploited Ejs vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss three-quarters of this vendor portfolio.
- 25%
- Covered by CISA
- 75%
- Beyond CISA
- 4
- Product families
Attested Ejs vulnerabilities
4 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2024-53900
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. |
Mongoose | High | Beyond CISA | 18 Sep 2026 |
|
CVE-2023-29827
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the... |
EJS | High | Beyond CISA | 18 Sep 2026 |
|
CVE-2026-39364
Vite has a `server.fs.deny` bypass with queries |
vite, vite-plus | Confirmed | Beyond CISA | 15 Sep 2026 |
|
CVE-2025-31125
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query |
vite | Confirmed | In CISA | 01 Jun 2026 |
No Ejs vulnerabilities match this search or filter.
Showing 4 of 4 on this page (4 Ejs known exploited vulnerabilities).
Recurring weakness patterns
Access control, incorrect behavior order: validate before canonicalize, and exposure account for four mapped occurrences across this Ejs KEV portfolio.
CWE-284
Improper Access Control
CWE-180
Incorrect Behavior Order: Validate Before Canonicalize
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-472
External Control of Assumed-Immutable Web Parameter
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')