thymeleaf
- Products in analyzed data
- 3
- Catalog vulnerabilities
- 5
Severity across 3 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 3 analyzed records
A short verification protects source data and prevents automated AI requests.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-41901Thymeleaf: Improper recognition of unauthorized syntax patterns in sandboxed Thymeleaf expressions | Exploitation statusNot known exploited | FixYes | Affected productthymeleaf | Published05/12/2026 | SeverityCritical |
CVE-2026-40478Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf | Exploitation statusNot known exploited | FixYes | Affected productthymeleaf | Published04/17/2026 | SeverityCritical |
CVE-2026-40477Improper restriction of the scope of accessible objects in Thymeleaf expressions | Exploitation statusNot known exploited | FixYes | Affected productthymeleaf | Published04/17/2026 | SeverityCritical |
CVE-2023-38286CVE-2023-38286 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published07/14/2023 | SeverityUnknown |
CVE-2021-43466CVE-2021-43466 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published11/09/2021 | SeverityUnknown |