İçeriğe atla
Noroxi

CWE-1336 · 173 kayıt

Improper Neutralization of Special Elements Used in a Template Engine

Bu sınıftaki CVE’ler

173 kayıt

  • Unauthenticated arbitrary file read and remote code execution in CrushFTP

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    crushftp · crushftp22 Nis 2024

  • Rejetto HTTP File Server 2.3m Unauthenticated RCE

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    rejetto · http file server31 May 2024

  • CVE-2026-75650
    71Bu hafta

    Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %4

    adobe · commerce7 Eyl 2026

  • CVE-2024-32651
    65Bu hafta

    Server Side Template Injection in Jinja2 allows Remote Command Execution

    KritikCVSS 10,0Kavram kanıtıEPSS %84

    dgtlmoon · changedetection.io25 Nis 2024

  • CVE-2025-47916
    64Bu hafta

    Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php.

    KritikCVSS 9,8SilahlaştırılmışEPSS %84

    invisioncommunity · invisioncommunity16 May 2025

  • CVE-2022-25813
    50Planlayın

    Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz

    YüksekCVSS 7,5Kavram kanıtıEPSS %67

    apache · ofbiz2 Eyl 2022

  • CVE-2024-24724
    47Planlayın

    Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution

    KritikCVSS 9,8Kavram kanıtıEPSS %26

    gibbonedu · gibbon2 Nis 2024

  • CVE-2024-6386
    43Planlayın

    WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection

    YüksekCVSS 8,8Kavram kanıtıEPSS %26

    wpml · wpml21 Ağu 2024

  • CVE-2025-53833
    43Planlayın

    LaRecipe is vulnerable to Server-Side Template Injection attacks

    KritikCVSS 10,0Kavram kanıtıEPSS %9

    saleem-hadad · larecipe14 Tem 2025

  • CVE-2025-14700
    41Planlayın

    Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller

    KritikCVSS 9,9Kavram kanıtıEPSS %7

    craftycontrol · crafty controller16 Ara 2025

  • CVE-2025-59340
    41Planlayın

    jinjava Sandbox Bypass via JavaType-Based Deserialization

    KritikCVSS 10,0İstismar yokEPSS %2

    hubspot · jinjava17 Eyl 2025

  • CVE-2025-49619
    40Planlayın

    Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation

    YüksekCVSS 8,5SilahlaştırılmışEPSS %20

    skyvern · skyvern7 Haz 2025

  • CVE-2025-23211
    40Planlayın

    Tandoor Recipes - SSTI - Remote Code Execution

    KritikCVSS 9,9Kavram kanıtıEPSS %4

    tandoor · recipes28 Oca 2025

  • CVE-2026-48323
    40Planlayın

    Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

    KritikCVSS 10,0İstismar yokEPSS %1

    adobe · campaign3 Ağu 2026

  • CVE-2026-97359
    40Planlayın

    HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection

    KritikCVSS 10,0İstismar yokEPSS %1

    rejetto · hfs25 gün önce

  • CVE-2026-44181
    40Planlayın

    Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution

    KritikCVSS 10,0İstismar yokEPSS %1

    jupyter · enterprise gateway16 Tem 2026

  • CVE-2024-12583
    39İzleyin

    Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection

    KritikCVSS 9,9Kavram kanıtıEPSS %1

    alexacrm · dynamics 365 integration4 Oca 2025

  • CVE-2026-52889
    39İzleyin

    Formie: Server-Side Template Injection in Formie Hidden field defaults

    KritikCVSS 9,8İstismar yokEPSS %1

    verbb · formie19 Ağu 2026

  • CVE-2026-27641
    39İzleyin

    Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    jugmac00 · flask-reuploaded25 Şub 2026

  • CVE-2025-67843
    39İzleyin

    A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attac

    KritikCVSS 9,8İstismar yokEPSS %1

    mintlify · mintlify18 Ara 2025

  • CVE-2026-65974
    39İzleyin

    ERPNext: Server-Side Template Injection leading to Remote Code Execution

    KritikCVSS 9,9İstismar yokEPSS %1

    frappe · erpnext17 Ağu 2026

  • CVE-2026-25526
    39İzleyin

    JinJava Bypass through ForTag leads to Arbitrary Java Execution

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    hubspot · jinjava4 Şub 2026

  • CVE-2025-32461
    39İzleyin

    wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval.

    KritikCVSS 9,9İstismar yokEPSS %1

    tiki · tiki8 Nis 2025

  • CVE-2024-42355
    39İzleyin

    Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

    KritikCVSS 9,8İstismar yokEPSS %1

    shopware · shopware8 Ağu 2024

  • CVE-2026-66613
    39İzleyin

    WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    crocoblock. jetimpex inc. · jetengine19 Ağu 2026

Tüm zafiyet sınıfları