Skip to main content

CWE archive

CWE-1336 CVEs

Programmatic archive

184 CVEs tagged with CWE-133647 Critical, 81 High, 42 Medium, 14 Low, 0 Unrated.

CVE-2025-62369

Published Nov 4, 2025

Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Devel…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60355

Published Oct 28, 2025

zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-62416

Published Oct 16, 2025

Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the se…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37729

Published Oct 13, 2025

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive info…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-54287

Published Oct 2, 2025

Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the hos…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-10380

Published Sep 23, 2025

The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template Injection in all versions up to, and including, 3.7.19. This…

CVSS 8.8 · High
evidence mentions
3
Buzz score
23.9

CVE-2025-59340

Published Sep 17, 2025

jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.8.1, by using mapper.getTypeFactory().constructFromCanonica…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-52122

Published Aug 27, 2025

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-35113

Published Aug 26, 2025

Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by loading a s…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57811

Published Aug 25, 2025

Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig S…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-9094

Published Aug 17, 2025

A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-53909

Published Jul 17, 2025

mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notif…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-34300

Published Jul 16, 2025

A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ciwweb.pl http://ciwweb.pl/  Perl web application. Exploitati…

CVSS 10.0 · Critical

CVE-2025-49828

Published Jul 15, 2025

Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conju…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-53833

Published Jul 14, 2025

LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (…

CVSS 10.0 · Critical

CVE-2025-6761

Published Jun 27, 2025

A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical. Affected by this issue is the function plugin.buildMobileP…

CVSS 5.5 · Medium

CVE-2025-6518

Published Jun 23, 2025

A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the function SingleLLMCallNode of the file backend/pyspur/nodes/llm/si…

CVSS 2.1 · Low

CVE-2025-49142

Published Jun 10, 2025

Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions prior to 2.4.10 or prior to 1.6.32 are potentially affected. Due to insuffici…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49136

Published Jun 9, 2025

listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functions whic…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-49619

Published Jun 7, 2025

Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinj…

CVSS 8.5 · High

CVE-2025-5325

Published May 29, 2025

A vulnerability has been found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as critical. Affected by this vulnerability is an unknown f…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47916

Published May 16, 2025

Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applic…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-46731

Published May 5, 2025

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vul…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-23376

Published Apr 28, 2025

Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-46661

Published Apr 28, 2025

IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template expressions, aka Server-Side Tem…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 101-125 of 184 CVEsPage 5 of 8