Перейти к содержимому
Noroxi

CWE-1336 · 173 записей

Improper Neutralization of Special Elements Used in a Template Engine

CVE этого класса

173 записей

  • CVE-2024-4040
    100Срочно

    Unauthenticated arbitrary file read and remote code execution in CrushFTP

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    crushftp · crushftp22 апр. 2024 г.

  • CVE-2024-23692
    99Срочно

    Rejetto HTTP File Server 2.3m Unauthenticated RCE

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    rejetto · http file server31 мая 2024 г.

  • CVE-2026-75650
    71На этой неделе

    Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 4 %

    adobe · commerce7 сент. 2026 г.

  • CVE-2024-32651
    65На этой неделе

    Server Side Template Injection in Jinja2 allows Remote Command Execution

    КритическаяCVSS 10,0Proof of conceptEPSS 84 %

    dgtlmoon · changedetection.io25 апр. 2024 г.

  • CVE-2025-47916
    64На этой неделе

    Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 84 %

    invisioncommunity · invisioncommunity16 мая 2025 г.

  • CVE-2022-25813
    50В плане

    Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz

    ВысокаяCVSS 7,5Proof of conceptEPSS 67 %

    apache · ofbiz2 сент. 2022 г.

  • CVE-2024-24724
    47В плане

    Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution

    КритическаяCVSS 9,8Proof of conceptEPSS 26 %

    gibbonedu · gibbon2 апр. 2024 г.

  • CVE-2024-6386
    43В плане

    WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection

    ВысокаяCVSS 8,8Proof of conceptEPSS 26 %

    wpml · wpml21 авг. 2024 г.

  • CVE-2025-53833
    43В плане

    LaRecipe is vulnerable to Server-Side Template Injection attacks

    КритическаяCVSS 10,0Proof of conceptEPSS 9 %

    saleem-hadad · larecipe14 июл. 2025 г.

  • CVE-2025-14700
    41В плане

    Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller

    КритическаяCVSS 9,9Proof of conceptEPSS 7 %

    craftycontrol · crafty controller16 дек. 2025 г.

  • CVE-2025-59340
    41В плане

    jinjava Sandbox Bypass via JavaType-Based Deserialization

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    hubspot · jinjava17 сент. 2025 г.

  • CVE-2025-49619
    40В плане

    Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation

    ВысокаяCVSS 8,5Готовый эксплойтEPSS 20 %

    skyvern · skyvern7 июн. 2025 г.

  • CVE-2025-23211
    40В плане

    Tandoor Recipes - SSTI - Remote Code Execution

    КритическаяCVSS 9,9Proof of conceptEPSS 4 %

    tandoor · recipes28 янв. 2025 г.

  • CVE-2026-48323
    40В плане

    Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    adobe · campaign3 авг. 2026 г.

  • CVE-2026-97359
    40В плане

    HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    rejetto · hfs25 дней назад

  • CVE-2026-44181
    40В плане

    Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    jupyter · enterprise gateway16 июл. 2026 г.

  • CVE-2024-12583
    39Наблюдать

    Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection

    КритическаяCVSS 9,9Proof of conceptEPSS 1 %

    alexacrm · dynamics 365 integration4 янв. 2025 г.

  • CVE-2026-52889
    39Наблюдать

    Formie: Server-Side Template Injection in Formie Hidden field defaults

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    verbb · formie19 авг. 2026 г.

  • CVE-2026-27641
    39Наблюдать

    Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection

    КритическаяCVSS 9,8Proof of conceptEPSS 1 %

    jugmac00 · flask-reuploaded25 февр. 2026 г.

  • CVE-2025-67843
    39Наблюдать

    A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attac

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    mintlify · mintlify18 дек. 2025 г.

  • CVE-2026-65974
    39Наблюдать

    ERPNext: Server-Side Template Injection leading to Remote Code Execution

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    frappe · erpnext17 авг. 2026 г.

  • CVE-2026-25526
    39Наблюдать

    JinJava Bypass through ForTag leads to Arbitrary Java Execution

    КритическаяCVSS 9,8Proof of conceptEPSS 1 %

    hubspot · jinjava4 февр. 2026 г.

  • CVE-2025-32461
    39Наблюдать

    wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval.

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    tiki · tiki8 апр. 2025 г.

  • CVE-2024-42355
    39Наблюдать

    Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    shopware · shopware8 авг. 2024 г.

  • CVE-2026-66613
    39Наблюдать

    WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    crocoblock. jetimpex inc. · jetengine19 авг. 2026 г.

Все классы уязвимостей