CWE-1336 · 173 records
Improper Neutralization of Special Elements Used in a Template Engine
CVEs in this class
173 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2024-4040Weaponized | Unauthenticated arbitrary file read and remote code execution in CrushFTPcrushftp · crushftp · CWE-1336 | Critical10.0 | KEV | 99.5% | Apr 22, 2024 |
99Now | CVE-2024-23692Weaponized | Rejetto HTTP File Server 2.3m Unauthenticated RCErejetto · http file server · CWE-1336 | Critical9.8 | KEV | 99.5% | May 31, 2024 |
71This week | CVE-2026-75650Weaponized | Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)adobe · commerce · CWE-1336 | Critical10.0 | KEV | 3.9% | Sep 7, 2026 |
65This week | CVE-2024-32651Proof of concept | Server Side Template Injection in Jinja2 allows Remote Command Executiondgtlmoon · changedetection.io · CWE-1336 | Critical10.0 | — | 83.6% | Apr 25, 2024 |
64This week | CVE-2025-47916Weaponized | Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php.invisioncommunity · invisioncommunity · CWE-1336 | Critical9.8 | — | 83.7% | May 16, 2025 |
50Plan | CVE-2022-25813Proof of concept | Server-Side Template Injection affecting the ecommerce plugin of Apache OFBizapache · ofbiz · CWE-1336 | High7.5 | — | 67.3% | Sep 2, 2022 |
47Plan | CVE-2024-24724Proof of concept | Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution gibbonedu · gibbon · CWE-1336 | Critical9.8 | — | 26.1% | Apr 2, 2024 |
43Plan | CVE-2024-6386Proof of concept | WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injectionwpml · wpml · CWE-1336 | High8.8 | — | 25.5% | Aug 21, 2024 |
43Plan | CVE-2025-53833Proof of concept | LaRecipe is vulnerable to Server-Side Template Injection attackssaleem-hadad · larecipe · CWE-1336 | Critical10.0 | — | 9.4% | Jul 14, 2025 |
41Plan | CVE-2025-14700Proof of concept | Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controllercraftycontrol · crafty controller · CWE-1336 | Critical9.9 | — | 6.6% | Dec 16, 2025 |
41Plan | CVE-2025-59340No exploit | jinjava Sandbox Bypass via JavaType-Based Deserializationhubspot · jinjava · CWE-1336 | Critical10.0 | — | 2.1% | Sep 17, 2025 |
40Plan | CVE-2025-49619Weaponized | Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation skyvern · skyvern · CWE-1336 | High8.5 | — | 20.0% | Jun 7, 2025 |
40Plan | CVE-2025-23211Proof of concept | Tandoor Recipes - SSTI - Remote Code Executiontandoor · recipes · CWE-1336 | Critical9.9 | — | 3.6% | Jan 28, 2025 |
40Plan | CVE-2026-48323No exploit | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)adobe · campaign · CWE-1336 | Critical10.0 | — | 1.4% | Aug 3, 2026 |
40Plan | CVE-2026-97359No exploit | HFS2 2.4.0 RCE via Multipart Upload Filename Template Injectionrejetto · hfs2 · CWE-1336 | Critical10.0 | — | 0.8% | 5 days ago |
40Plan | CVE-2026-44181No exploit | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Executionjupyter · enterprise gateway · CWE-1336 | Critical10.0 | — | 0.8% | Jul 16, 2026 |
39Monitor | CVE-2024-12583Proof of concept | Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injectionalexacrm · dynamics 365 integration · CWE-1336 | Critical9.9 | — | 1.4% | Jan 4, 2025 |
39Monitor | CVE-2026-52889No exploit | Formie: Server-Side Template Injection in Formie Hidden field defaultsverbb · formie · CWE-1336 | Critical9.8 | — | 1.3% | Aug 19, 2026 |
39Monitor | CVE-2026-27641Proof of concept | Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injectionjugmac00 · flask-reuploaded · CWE-1336 | Critical9.8 | — | 1.2% | Feb 25, 2026 |
39Monitor | CVE-2025-67843No exploit | A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attacmintlify · mintlify · CWE-1336 | Critical9.8 | — | 1.1% | Dec 18, 2025 |
39Monitor | CVE-2026-65974No exploit | ERPNext: Server-Side Template Injection leading to Remote Code Executionfrappe · erpnext · CWE-1336 | Critical9.9 | — | 1.0% | Aug 17, 2026 |
39Monitor | CVE-2026-25526Proof of concept | JinJava Bypass through ForTag leads to Arbitrary Java Executionhubspot · jinjava · CWE-1336 | Critical9.8 | — | 0.9% | Feb 4, 2026 |
39Monitor | CVE-2025-32461No exploit | wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval.tiki · tiki · CWE-1336 | Critical9.9 | — | 0.9% | Apr 8, 2025 |
39Monitor | CVE-2024-42355No exploit | Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagshopware · shopware · CWE-1336 | Critical9.8 | — | 0.9% | Aug 8, 2024 |
39Monitor | CVE-2026-66613No exploit | WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerabilitycrocoblock. jetimpex inc. · jetengine · CWE-1336 | Critical9.8 | — | 0.9% | Aug 19, 2026 |
- CVE-2024-4040100Now
Unauthenticated arbitrary file read and remote code execution in CrushFTP
CriticalCVSS 10.0KEVWeaponizedEPSS 100%crushftp · crushftpApr 22, 2024
- CVE-2024-2369299Now
Rejetto HTTP File Server 2.3m Unauthenticated RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 99%rejetto · http file serverMay 31, 2024
- CVE-2026-7565071This week
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
CriticalCVSS 10.0KEVWeaponizedEPSS 4%adobe · commerceSep 7, 2026
- CVE-2024-3265165This week
Server Side Template Injection in Jinja2 allows Remote Command Execution
CriticalCVSS 10.0Proof of conceptEPSS 84%dgtlmoon · changedetection.ioApr 25, 2024
- CVE-2025-4791664This week
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php.
CriticalCVSS 9.8WeaponizedEPSS 84%invisioncommunity · invisioncommunityMay 16, 2025
- CVE-2022-2581350Plan
Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz
HighCVSS 7.5Proof of conceptEPSS 67%apache · ofbizSep 2, 2022
- CVE-2024-2472447Plan
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution
CriticalCVSS 9.8Proof of conceptEPSS 26%gibbonedu · gibbonApr 2, 2024
- CVE-2024-638643Plan
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
HighCVSS 8.8Proof of conceptEPSS 26%wpml · wpmlAug 21, 2024
- CVE-2025-5383343Plan
LaRecipe is vulnerable to Server-Side Template Injection attacks
CriticalCVSS 10.0Proof of conceptEPSS 9%saleem-hadad · larecipeJul 14, 2025
- CVE-2025-1470041Plan
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
CriticalCVSS 9.9Proof of conceptEPSS 7%craftycontrol · crafty controllerDec 16, 2025
- CVE-2025-5934041Plan
jinjava Sandbox Bypass via JavaType-Based Deserialization
CriticalCVSS 10.0No exploitEPSS 2%hubspot · jinjavaSep 17, 2025
- CVE-2025-4961940Plan
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation
HighCVSS 8.5WeaponizedEPSS 20%skyvern · skyvernJun 7, 2025
- CVE-2025-2321140Plan
Tandoor Recipes - SSTI - Remote Code Execution
CriticalCVSS 9.9Proof of conceptEPSS 4%tandoor · recipesJan 28, 2025
- CVE-2026-4832340Plan
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
CriticalCVSS 10.0No exploitEPSS 1%adobe · campaignAug 3, 2026
- CVE-2026-9735940Plan
HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection
CriticalCVSS 10.0No exploitEPSS 1%rejetto · hfs25 days ago
- CVE-2026-4418140Plan
Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution
CriticalCVSS 10.0No exploitEPSS 1%jupyter · enterprise gatewayJul 16, 2026
- CVE-2024-1258339Monitor
Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection
CriticalCVSS 9.9Proof of conceptEPSS 1%alexacrm · dynamics 365 integrationJan 4, 2025
- CVE-2026-5288939Monitor
Formie: Server-Side Template Injection in Formie Hidden field defaults
CriticalCVSS 9.8No exploitEPSS 1%verbb · formieAug 19, 2026
- CVE-2026-2764139Monitor
Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection
CriticalCVSS 9.8Proof of conceptEPSS 1%jugmac00 · flask-reuploadedFeb 25, 2026
- CVE-2025-6784339Monitor
A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attac
CriticalCVSS 9.8No exploitEPSS 1%mintlify · mintlifyDec 18, 2025
- CVE-2026-6597439Monitor
ERPNext: Server-Side Template Injection leading to Remote Code Execution
CriticalCVSS 9.9No exploitEPSS 1%frappe · erpnextAug 17, 2026
- CVE-2026-2552639Monitor
JinJava Bypass through ForTag leads to Arbitrary Java Execution
CriticalCVSS 9.8Proof of conceptEPSS 1%hubspot · jinjavaFeb 4, 2026
- CVE-2025-3246139Monitor
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval.
CriticalCVSS 9.9No exploitEPSS 1%tiki · tikiApr 8, 2025
- CVE-2024-4235539Monitor
Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
CriticalCVSS 9.8No exploitEPSS 1%shopware · shopwareAug 8, 2024
- CVE-2026-6661339Monitor
WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability
CriticalCVSS 9.8No exploitEPSS 1%crocoblock. jetimpex inc. · jetengineAug 19, 2026