Skip to main content

CWE archive

CWE-1336 CVEs

Programmatic archive

184 CVEs tagged with CWE-133647 Critical, 81 High, 42 Medium, 14 Low, 0 Unrated.

CVE-2026-23626

Published Jan 18, 2026

Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a Twig sandbox with an overly permissive security policy (`De…

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-22244

Published Jan 8, 2026

OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templat…

CVSS 8.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-68454

Published Jan 5, 2026

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Executi…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-21450

Published Jan 2, 2026

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code e…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21449

Published Jan 2, 2026

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege u…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21448

Published Jan 2, 2026

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-68929

Published Dec 29, 2025

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a speciall…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-67843

Published Dec 19, 2025

A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to execute arbitrary code via inli…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14700

Published Dec 17, 2025

An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Si…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-14731

Published Dec 16, 2025

A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-66438

Published Dec 15, 2025

A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, the API frappe.www.printview.get…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66437

Published Dec 15, 2025

An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using fr…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66436

Published Dec 15, 2025

An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Ji…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66435

Published Dec 15, 2025

An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66434

Published Dec 15, 2025

An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jin…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-58303

Published Dec 11, 2025

FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute…

CVSS 8.6 · High

CVE-2024-58293

Published Dec 11, 2025

Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Att…

CVSS 8.6 · High

CVE-2025-65602

Published Dec 10, 2025

A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66299

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permiss…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66298

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66297

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the pag…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66294

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor per…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66361

Published Nov 28, 2025

An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65106

Published Nov 21, 2025

LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChai…

CVSS 8.3 · High
Showing 76-100 of 184 CVEsPage 4 of 8