CWE-1336 · 173 записей
Improper Neutralization of Special Elements Used in a Template Engine
CVE этого класса
173 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2024-4040Готовый эксплойт | Unauthenticated arbitrary file read and remote code execution in CrushFTPcrushftp · crushftp · CWE-1336 | Критическая10,0 | KEV | 99,5 % | 22 апр. 2024 г. |
99Срочно | CVE-2024-23692Готовый эксплойт | Rejetto HTTP File Server 2.3m Unauthenticated RCErejetto · http file server · CWE-1336 | Критическая9,8 | KEV | 99,5 % | 31 мая 2024 г. |
71На этой неделе | CVE-2026-75650Готовый эксплойт | Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)adobe · commerce · CWE-1336 | Критическая10,0 | KEV | 3,9 % | 7 сент. 2026 г. |
65На этой неделе | CVE-2024-32651Proof of concept | Server Side Template Injection in Jinja2 allows Remote Command Executiondgtlmoon · changedetection.io · CWE-1336 | Критическая10,0 | — | 83,6 % | 25 апр. 2024 г. |
64На этой неделе | CVE-2025-47916Готовый эксплойт | Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php.invisioncommunity · invisioncommunity · CWE-1336 | Критическая9,8 | — | 83,7 % | 16 мая 2025 г. |
50В плане | CVE-2022-25813Proof of concept | Server-Side Template Injection affecting the ecommerce plugin of Apache OFBizapache · ofbiz · CWE-1336 | Высокая7,5 | — | 67,3 % | 2 сент. 2022 г. |
47В плане | CVE-2024-24724Proof of concept | Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution gibbonedu · gibbon · CWE-1336 | Критическая9,8 | — | 26,1 % | 2 апр. 2024 г. |
43В плане | CVE-2024-6386Proof of concept | WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injectionwpml · wpml · CWE-1336 | Высокая8,8 | — | 25,5 % | 21 авг. 2024 г. |
43В плане | CVE-2025-53833Proof of concept | LaRecipe is vulnerable to Server-Side Template Injection attackssaleem-hadad · larecipe · CWE-1336 | Критическая10,0 | — | 9,4 % | 14 июл. 2025 г. |
41В плане | CVE-2025-14700Proof of concept | Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controllercraftycontrol · crafty controller · CWE-1336 | Критическая9,9 | — | 6,6 % | 16 дек. 2025 г. |
41В плане | CVE-2025-59340Эксплойта нет | jinjava Sandbox Bypass via JavaType-Based Deserializationhubspot · jinjava · CWE-1336 | Критическая10,0 | — | 2,1 % | 17 сент. 2025 г. |
40В плане | CVE-2025-49619Готовый эксплойт | Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation skyvern · skyvern · CWE-1336 | Высокая8,5 | — | 20,0 % | 7 июн. 2025 г. |
40В плане | CVE-2025-23211Proof of concept | Tandoor Recipes - SSTI - Remote Code Executiontandoor · recipes · CWE-1336 | Критическая9,9 | — | 3,6 % | 28 янв. 2025 г. |
40В плане | CVE-2026-48323Эксплойта нет | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)adobe · campaign · CWE-1336 | Критическая10,0 | — | 1,4 % | 3 авг. 2026 г. |
40В плане | CVE-2026-97359Эксплойта нет | HFS2 2.4.0 RCE via Multipart Upload Filename Template Injectionrejetto · hfs2 · CWE-1336 | Критическая10,0 | — | 0,8 % | 5 дней назад |
40В плане | CVE-2026-44181Эксплойта нет | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Executionjupyter · enterprise gateway · CWE-1336 | Критическая10,0 | — | 0,8 % | 16 июл. 2026 г. |
39Наблюдать | CVE-2024-12583Proof of concept | Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injectionalexacrm · dynamics 365 integration · CWE-1336 | Критическая9,9 | — | 1,4 % | 4 янв. 2025 г. |
39Наблюдать | CVE-2026-52889Эксплойта нет | Formie: Server-Side Template Injection in Formie Hidden field defaultsverbb · formie · CWE-1336 | Критическая9,8 | — | 1,3 % | 19 авг. 2026 г. |
39Наблюдать | CVE-2026-27641Proof of concept | Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injectionjugmac00 · flask-reuploaded · CWE-1336 | Критическая9,8 | — | 1,2 % | 25 февр. 2026 г. |
39Наблюдать | CVE-2025-67843Эксплойта нет | A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attacmintlify · mintlify · CWE-1336 | Критическая9,8 | — | 1,1 % | 18 дек. 2025 г. |
39Наблюдать | CVE-2026-65974Эксплойта нет | ERPNext: Server-Side Template Injection leading to Remote Code Executionfrappe · erpnext · CWE-1336 | Критическая9,9 | — | 1,0 % | 17 авг. 2026 г. |
39Наблюдать | CVE-2026-25526Proof of concept | JinJava Bypass through ForTag leads to Arbitrary Java Executionhubspot · jinjava · CWE-1336 | Критическая9,8 | — | 0,9 % | 4 февр. 2026 г. |
39Наблюдать | CVE-2025-32461Эксплойта нет | wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval.tiki · tiki · CWE-1336 | Критическая9,9 | — | 0,9 % | 8 апр. 2025 г. |
39Наблюдать | CVE-2024-42355Эксплойта нет | Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagshopware · shopware · CWE-1336 | Критическая9,8 | — | 0,9 % | 8 авг. 2024 г. |
39Наблюдать | CVE-2026-66613Эксплойта нет | WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerabilitycrocoblock. jetimpex inc. · jetengine · CWE-1336 | Критическая9,8 | — | 0,9 % | 19 авг. 2026 г. |
- CVE-2024-4040100Срочно
Unauthenticated arbitrary file read and remote code execution in CrushFTP
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %crushftp · crushftp22 апр. 2024 г.
- CVE-2024-2369299Срочно
Rejetto HTTP File Server 2.3m Unauthenticated RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %rejetto · http file server31 мая 2024 г.
- CVE-2026-7565071На этой неделе
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 4 %adobe · commerce7 сент. 2026 г.
- CVE-2024-3265165На этой неделе
Server Side Template Injection in Jinja2 allows Remote Command Execution
КритическаяCVSS 10,0Proof of conceptEPSS 84 %dgtlmoon · changedetection.io25 апр. 2024 г.
- CVE-2025-4791664На этой неделе
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php.
КритическаяCVSS 9,8Готовый эксплойтEPSS 84 %invisioncommunity · invisioncommunity16 мая 2025 г.
- CVE-2022-2581350В плане
Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz
ВысокаяCVSS 7,5Proof of conceptEPSS 67 %apache · ofbiz2 сент. 2022 г.
- CVE-2024-2472447В плане
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution
КритическаяCVSS 9,8Proof of conceptEPSS 26 %gibbonedu · gibbon2 апр. 2024 г.
- CVE-2024-638643В плане
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
ВысокаяCVSS 8,8Proof of conceptEPSS 26 %wpml · wpml21 авг. 2024 г.
- CVE-2025-5383343В плане
LaRecipe is vulnerable to Server-Side Template Injection attacks
КритическаяCVSS 10,0Proof of conceptEPSS 9 %saleem-hadad · larecipe14 июл. 2025 г.
- CVE-2025-1470041В плане
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
КритическаяCVSS 9,9Proof of conceptEPSS 7 %craftycontrol · crafty controller16 дек. 2025 г.
- CVE-2025-5934041В плане
jinjava Sandbox Bypass via JavaType-Based Deserialization
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %hubspot · jinjava17 сент. 2025 г.
- CVE-2025-4961940В плане
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation
ВысокаяCVSS 8,5Готовый эксплойтEPSS 20 %skyvern · skyvern7 июн. 2025 г.
- CVE-2025-2321140В плане
Tandoor Recipes - SSTI - Remote Code Execution
КритическаяCVSS 9,9Proof of conceptEPSS 4 %tandoor · recipes28 янв. 2025 г.
- CVE-2026-4832340В плане
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %adobe · campaign3 авг. 2026 г.
- CVE-2026-9735940В плане
HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %rejetto · hfs25 дней назад
- CVE-2026-4418140В плане
Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %jupyter · enterprise gateway16 июл. 2026 г.
- CVE-2024-1258339Наблюдать
Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection
КритическаяCVSS 9,9Proof of conceptEPSS 1 %alexacrm · dynamics 365 integration4 янв. 2025 г.
- CVE-2026-5288939Наблюдать
Formie: Server-Side Template Injection in Formie Hidden field defaults
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %verbb · formie19 авг. 2026 г.
- CVE-2026-2764139Наблюдать
Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection
КритическаяCVSS 9,8Proof of conceptEPSS 1 %jugmac00 · flask-reuploaded25 февр. 2026 г.
- CVE-2025-6784339Наблюдать
A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attac
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mintlify · mintlify18 дек. 2025 г.
- CVE-2026-6597439Наблюдать
ERPNext: Server-Side Template Injection leading to Remote Code Execution
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %frappe · erpnext17 авг. 2026 г.
- CVE-2026-2552639Наблюдать
JinJava Bypass through ForTag leads to Arbitrary Java Execution
КритическаяCVSS 9,8Proof of conceptEPSS 1 %hubspot · jinjava4 февр. 2026 г.
- CVE-2025-3246139Наблюдать
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval.
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %tiki · tiki8 апр. 2025 г.
- CVE-2024-4235539Наблюдать
Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %shopware · shopware8 авг. 2024 г.
- CVE-2026-6661339Наблюдать
WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %crocoblock. jetimpex inc. · jetengine19 авг. 2026 г.