Underscore Underscorejs Underscore

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Underscorejs Underscore.

By the Year

In 2025 there have been 0 vulnerabilities in Underscorejs Underscore. Underscore did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 1 7.20
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Underscore vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Underscorejs Underscore Security Vulnerabilities

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection

CVE-2021-23358 7.2 - High - March 29, 2021

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

Code Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Oracle or by Underscorejs? Click the Watch button to subscribe.

subscribe