Skip to content
Noroxi

CWE-1336 · 173 records

Improper Neutralization of Special Elements Used in a Template Engine

CVEs in this class

173 records

  • Unauthenticated arbitrary file read and remote code execution in CrushFTP

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    crushftp · crushftpApr 22, 2024

  • Rejetto HTTP File Server 2.3m Unauthenticated RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    rejetto · http file serverMay 31, 2024

  • CVE-2026-75650
    71This week

    Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

    CriticalCVSS 10.0KEVWeaponizedEPSS 4%

    adobe · commerceSep 7, 2026

  • CVE-2024-32651
    65This week

    Server Side Template Injection in Jinja2 allows Remote Command Execution

    CriticalCVSS 10.0Proof of conceptEPSS 84%

    dgtlmoon · changedetection.ioApr 25, 2024

  • CVE-2025-47916
    64This week

    Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php.

    CriticalCVSS 9.8WeaponizedEPSS 84%

    invisioncommunity · invisioncommunityMay 16, 2025

  • Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz

    HighCVSS 7.5Proof of conceptEPSS 67%

    apache · ofbizSep 2, 2022

  • Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution

    CriticalCVSS 9.8Proof of conceptEPSS 26%

    gibbonedu · gibbonApr 2, 2024

  • WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection

    HighCVSS 8.8Proof of conceptEPSS 26%

    wpml · wpmlAug 21, 2024

  • LaRecipe is vulnerable to Server-Side Template Injection attacks

    CriticalCVSS 10.0Proof of conceptEPSS 9%

    saleem-hadad · larecipeJul 14, 2025

  • Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller

    CriticalCVSS 9.9Proof of conceptEPSS 7%

    craftycontrol · crafty controllerDec 16, 2025

  • jinjava Sandbox Bypass via JavaType-Based Deserialization

    CriticalCVSS 10.0No exploitEPSS 2%

    hubspot · jinjavaSep 17, 2025

  • Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation

    HighCVSS 8.5WeaponizedEPSS 20%

    skyvern · skyvernJun 7, 2025

  • Tandoor Recipes - SSTI - Remote Code Execution

    CriticalCVSS 9.9Proof of conceptEPSS 4%

    tandoor · recipesJan 28, 2025

  • Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

    CriticalCVSS 10.0No exploitEPSS 1%

    adobe · campaignAug 3, 2026

  • HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection

    CriticalCVSS 10.0No exploitEPSS 1%

    rejetto · hfs25 days ago

  • Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution

    CriticalCVSS 10.0No exploitEPSS 1%

    jupyter · enterprise gatewayJul 16, 2026

  • Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection

    CriticalCVSS 9.9Proof of conceptEPSS 1%

    alexacrm · dynamics 365 integrationJan 4, 2025

  • Formie: Server-Side Template Injection in Formie Hidden field defaults

    CriticalCVSS 9.8No exploitEPSS 1%

    verbb · formieAug 19, 2026

  • Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    jugmac00 · flask-reuploadedFeb 25, 2026

  • A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attac

    CriticalCVSS 9.8No exploitEPSS 1%

    mintlify · mintlifyDec 18, 2025

  • ERPNext: Server-Side Template Injection leading to Remote Code Execution

    CriticalCVSS 9.9No exploitEPSS 1%

    frappe · erpnextAug 17, 2026

  • JinJava Bypass through ForTag leads to Arbitrary Java Execution

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    hubspot · jinjavaFeb 4, 2026

  • wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval.

    CriticalCVSS 9.9No exploitEPSS 1%

    tiki · tikiApr 8, 2025

  • Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

    CriticalCVSS 9.8No exploitEPSS 1%

    shopware · shopwareAug 8, 2024

  • WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    crocoblock. jetimpex inc. · jetengineAug 19, 2026

All vulnerability classes