CWE-1336 · 173 kayıt
Improper Neutralization of Special Elements Used in a Template Engine
Bu sınıftaki CVE’ler
173 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2024-4040Silahlaştırılmış | Unauthenticated arbitrary file read and remote code execution in CrushFTPcrushftp · crushftp · CWE-1336 | Kritik10,0 | KEV | %99,5 | 22 Nis 2024 |
99Hemen | CVE-2024-23692Silahlaştırılmış | Rejetto HTTP File Server 2.3m Unauthenticated RCErejetto · http file server · CWE-1336 | Kritik9,8 | KEV | %99,5 | 31 May 2024 |
71Bu hafta | CVE-2026-75650Silahlaştırılmış | Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)adobe · commerce · CWE-1336 | Kritik10,0 | KEV | %3,9 | 7 Eyl 2026 |
65Bu hafta | CVE-2024-32651Kavram kanıtı | Server Side Template Injection in Jinja2 allows Remote Command Executiondgtlmoon · changedetection.io · CWE-1336 | Kritik10,0 | — | %83,6 | 25 Nis 2024 |
64Bu hafta | CVE-2025-47916Silahlaştırılmış | Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php.invisioncommunity · invisioncommunity · CWE-1336 | Kritik9,8 | — | %83,7 | 16 May 2025 |
50Planlayın | CVE-2022-25813Kavram kanıtı | Server-Side Template Injection affecting the ecommerce plugin of Apache OFBizapache · ofbiz · CWE-1336 | Yüksek7,5 | — | %67,3 | 2 Eyl 2022 |
47Planlayın | CVE-2024-24724Kavram kanıtı | Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution gibbonedu · gibbon · CWE-1336 | Kritik9,8 | — | %26,1 | 2 Nis 2024 |
43Planlayın | CVE-2024-6386Kavram kanıtı | WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injectionwpml · wpml · CWE-1336 | Yüksek8,8 | — | %25,5 | 21 Ağu 2024 |
43Planlayın | CVE-2025-53833Kavram kanıtı | LaRecipe is vulnerable to Server-Side Template Injection attackssaleem-hadad · larecipe · CWE-1336 | Kritik10,0 | — | %9,4 | 14 Tem 2025 |
41Planlayın | CVE-2025-14700Kavram kanıtı | Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controllercraftycontrol · crafty controller · CWE-1336 | Kritik9,9 | — | %6,6 | 16 Ara 2025 |
41Planlayın | CVE-2025-59340İstismar yok | jinjava Sandbox Bypass via JavaType-Based Deserializationhubspot · jinjava · CWE-1336 | Kritik10,0 | — | %2,1 | 17 Eyl 2025 |
40Planlayın | CVE-2025-49619Silahlaştırılmış | Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation skyvern · skyvern · CWE-1336 | Yüksek8,5 | — | %20,0 | 7 Haz 2025 |
40Planlayın | CVE-2025-23211Kavram kanıtı | Tandoor Recipes - SSTI - Remote Code Executiontandoor · recipes · CWE-1336 | Kritik9,9 | — | %3,6 | 28 Oca 2025 |
40Planlayın | CVE-2026-48323İstismar yok | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)adobe · campaign · CWE-1336 | Kritik10,0 | — | %1,4 | 3 Ağu 2026 |
40Planlayın | CVE-2026-97359İstismar yok | HFS2 2.4.0 RCE via Multipart Upload Filename Template Injectionrejetto · hfs2 · CWE-1336 | Kritik10,0 | — | %0,8 | 5 gün önce |
40Planlayın | CVE-2026-44181İstismar yok | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Executionjupyter · enterprise gateway · CWE-1336 | Kritik10,0 | — | %0,8 | 16 Tem 2026 |
39İzleyin | CVE-2024-12583Kavram kanıtı | Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injectionalexacrm · dynamics 365 integration · CWE-1336 | Kritik9,9 | — | %1,4 | 4 Oca 2025 |
39İzleyin | CVE-2026-52889İstismar yok | Formie: Server-Side Template Injection in Formie Hidden field defaultsverbb · formie · CWE-1336 | Kritik9,8 | — | %1,3 | 19 Ağu 2026 |
39İzleyin | CVE-2026-27641Kavram kanıtı | Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injectionjugmac00 · flask-reuploaded · CWE-1336 | Kritik9,8 | — | %1,2 | 25 Şub 2026 |
39İzleyin | CVE-2025-67843İstismar yok | A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attacmintlify · mintlify · CWE-1336 | Kritik9,8 | — | %1,1 | 18 Ara 2025 |
39İzleyin | CVE-2026-65974İstismar yok | ERPNext: Server-Side Template Injection leading to Remote Code Executionfrappe · erpnext · CWE-1336 | Kritik9,9 | — | %1,0 | 17 Ağu 2026 |
39İzleyin | CVE-2026-25526Kavram kanıtı | JinJava Bypass through ForTag leads to Arbitrary Java Executionhubspot · jinjava · CWE-1336 | Kritik9,8 | — | %0,9 | 4 Şub 2026 |
39İzleyin | CVE-2025-32461İstismar yok | wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval.tiki · tiki · CWE-1336 | Kritik9,9 | — | %0,9 | 8 Nis 2025 |
39İzleyin | CVE-2024-42355İstismar yok | Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagshopware · shopware · CWE-1336 | Kritik9,8 | — | %0,9 | 8 Ağu 2024 |
39İzleyin | CVE-2026-66613İstismar yok | WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerabilitycrocoblock. jetimpex inc. · jetengine · CWE-1336 | Kritik9,8 | — | %0,9 | 19 Ağu 2026 |
- CVE-2024-4040100Hemen
Unauthenticated arbitrary file read and remote code execution in CrushFTP
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100crushftp · crushftp22 Nis 2024
- CVE-2024-2369299Hemen
Rejetto HTTP File Server 2.3m Unauthenticated RCE
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99rejetto · http file server31 May 2024
- CVE-2026-7565071Bu hafta
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %4adobe · commerce7 Eyl 2026
- CVE-2024-3265165Bu hafta
Server Side Template Injection in Jinja2 allows Remote Command Execution
KritikCVSS 10,0Kavram kanıtıEPSS %84dgtlmoon · changedetection.io25 Nis 2024
- CVE-2025-4791664Bu hafta
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php.
KritikCVSS 9,8SilahlaştırılmışEPSS %84invisioncommunity · invisioncommunity16 May 2025
- CVE-2022-2581350Planlayın
Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz
YüksekCVSS 7,5Kavram kanıtıEPSS %67apache · ofbiz2 Eyl 2022
- CVE-2024-2472447Planlayın
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution
KritikCVSS 9,8Kavram kanıtıEPSS %26gibbonedu · gibbon2 Nis 2024
- CVE-2024-638643Planlayın
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
YüksekCVSS 8,8Kavram kanıtıEPSS %26wpml · wpml21 Ağu 2024
- CVE-2025-5383343Planlayın
LaRecipe is vulnerable to Server-Side Template Injection attacks
KritikCVSS 10,0Kavram kanıtıEPSS %9saleem-hadad · larecipe14 Tem 2025
- CVE-2025-1470041Planlayın
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
KritikCVSS 9,9Kavram kanıtıEPSS %7craftycontrol · crafty controller16 Ara 2025
- CVE-2025-5934041Planlayın
jinjava Sandbox Bypass via JavaType-Based Deserialization
KritikCVSS 10,0İstismar yokEPSS %2hubspot · jinjava17 Eyl 2025
- CVE-2025-4961940Planlayın
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation
YüksekCVSS 8,5SilahlaştırılmışEPSS %20skyvern · skyvern7 Haz 2025
- CVE-2025-2321140Planlayın
Tandoor Recipes - SSTI - Remote Code Execution
KritikCVSS 9,9Kavram kanıtıEPSS %4tandoor · recipes28 Oca 2025
- CVE-2026-4832340Planlayın
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
KritikCVSS 10,0İstismar yokEPSS %1adobe · campaign3 Ağu 2026
- CVE-2026-9735940Planlayın
HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection
KritikCVSS 10,0İstismar yokEPSS %1rejetto · hfs25 gün önce
- CVE-2026-4418140Planlayın
Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution
KritikCVSS 10,0İstismar yokEPSS %1jupyter · enterprise gateway16 Tem 2026
- CVE-2024-1258339İzleyin
Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection
KritikCVSS 9,9Kavram kanıtıEPSS %1alexacrm · dynamics 365 integration4 Oca 2025
- CVE-2026-5288939İzleyin
Formie: Server-Side Template Injection in Formie Hidden field defaults
KritikCVSS 9,8İstismar yokEPSS %1verbb · formie19 Ağu 2026
- CVE-2026-2764139İzleyin
Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection
KritikCVSS 9,8Kavram kanıtıEPSS %1jugmac00 · flask-reuploaded25 Şub 2026
- CVE-2025-6784339İzleyin
A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attac
KritikCVSS 9,8İstismar yokEPSS %1mintlify · mintlify18 Ara 2025
- CVE-2026-6597439İzleyin
ERPNext: Server-Side Template Injection leading to Remote Code Execution
KritikCVSS 9,9İstismar yokEPSS %1frappe · erpnext17 Ağu 2026
- CVE-2026-2552639İzleyin
JinJava Bypass through ForTag leads to Arbitrary Java Execution
KritikCVSS 9,8Kavram kanıtıEPSS %1hubspot · jinjava4 Şub 2026
- CVE-2025-3246139İzleyin
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval.
KritikCVSS 9,9İstismar yokEPSS %1tiki · tiki8 Nis 2025
- CVE-2024-4235539İzleyin
Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag
KritikCVSS 9,8İstismar yokEPSS %1shopware · shopware8 Ağu 2024
- CVE-2026-6661339İzleyin
WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability
KritikCVSS 9,8İstismar yokEPSS %1crocoblock. jetimpex inc. · jetengine19 Ağu 2026