Yang Jun
9 exploits
Active since Mar 2026
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
CVSS 6.1
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body
CVSS 6.5
LiquidJS: `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`
CVSS 5.3
LiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime)
CVSS 7.5
LiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
CVSS 7.5
LiquidJS is vulnerable to Denial of Service via circular block reference in layout
CVSS 7.5
LiquidJS <10.25.4 sort_natural - Prototype Property Disclosure
CVSS 5.3
LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash
CVSS 7.5
liquidjs < 10.25.0 - Path Traversal via Layout, Render, and Include Tags
CVSS 7.5