Skip to main content

CWE archive

CWE-1336 CVEs

Programmatic archive

184 CVEs tagged with CWE-133647 Critical, 81 High, 42 Medium, 14 Low, 0 Unrated.

CVE-2025-3841

Published Apr 21, 2025

A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.p…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32461

Published Apr 9, 2025

wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.

CVSS 9.9 · Critical

CVE-2025-1040

Published Mar 20, 2025

AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from the impr…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-8238

Published Mar 20, 2025

In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26865

Published Mar 10, 2025

Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18.   It's a reg…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-2040

Published Mar 6, 2025

A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9150

Published Feb 21, 2025

Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might be included. An attacker is able use a low privileges acco…

CVSS 8.7 · High

CVE-2025-26789

Published Feb 14, 2025

An issue was discovered in Logpoint AgentX before 1.5.0. A vulnerability caused by limited access controls allowed li-admin users to access sensitive information about AgentX Mana…

CVSS 6.9 · Medium

CVE-2024-57177

Published Feb 10, 2025

A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation reques…

CVSS 7.3 · High

CVE-2024-54954

Published Feb 10, 2025

OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-23211

Published Jan 28, 2025

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server.…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-12583

Published Jan 4, 2025

The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side…

CVSS 9.9 · Critical

CVE-2024-56326

Published Dec 23, 2024

Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the cont…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55660

Published Dec 12, 2024

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection (SSTI) thr…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55652

Published Dec 12, 2024

PenDoc is a penetration testing reporting application. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an attacker can write a malicious docx template containing express…

CVSS 6.5 · Medium

CVE-2024-30372

Published Nov 22, 2024

Allegra getLinkText Server-Side Template Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installati…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48962

Published Nov 18, 2024

Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39766

Published Nov 13, 2024

Improper neutralization of special elements used in SQL command in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enab…

CVSS 7.3 · High

CVE-2024-46366

Published Sep 27, 2024

A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious pa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45053

Published Sep 4, 2024

Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input sanitiz…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6386

Published Aug 21, 2024

The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing i…

CVSS 9.9 · Critical
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2024-42356

Published Aug 8, 2024

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current lan…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42355

Published Aug 8, 2024

Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41950

Published Jul 31, 2024

Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vector search and more. Haystack clients that let their users cr…

CVSS 7.5 · High
Showing 126-150 of 184 CVEsPage 6 of 8