CWE-1336— Improper Neutralization of Special Elements Used in a Template Engine (SSTI)
156 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1336page 2 of 4
- CVE-2024-55652MEDIUMCVSS 6.5EG 6.52024-12-12
PenDoc is a penetration testing reporting application. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an attacker can write a malicious docx template containing expressions that escape the JavaScript sandbox to execute arbitrary…
- CVE-2024-55660CRITICALCVSS 9.8EG 9.82024-12-12
SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limi…
- CVE-2024-56326HIGHCVSS 7.8EG 7.82024-12-23
Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the content of a template to execute arbitrary Python code. To explo…
- CVE-2024-57177HIGHCVSS 7.3EG 4.32025-02-10
A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged t…
- CVE-2024-58293HIGHCVSS 8.6EG 0.02025-12-11
Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Attackers can inject template payloads in items, taxes, transac…
- CVE-2024-58303HIGHCVSS 8.6EG 0.02025-12-11
FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions t…
- CVE-2024-6386CRITICALCVSS 9.9EG 9.92024-08-21
The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. Thi…
- CVE-2024-8238HIGHCVSS 8.1EG 5.92025-03-20
In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against the str.format_map() method, allowing an attacker to leak ser…
- CVE-2024-9150HIGHCVSS 8.7EG 0.02025-02-21
Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might be included. An attacker is able use a low privileges account in order to abuse this functionality and execute malicio…
- CVE-2025-10380HIGHCVSS 8.8EG 8.82025-09-23
The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template Injection in all versions up to, and including, 3.7.19. This is due to insufficient input sanitization and lack of acc…
- CVE-2025-1040HIGHCVSS 8.8EG 8.82025-03-20
AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from the improper handling of user-supplied format strings in the `AgentO…
- CVE-2025-14700CRITICALCVSS 9.9EG 9.92025-12-17
An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.
- CVE-2025-14731MEDIUMCVSS 6.3EG 6.32025-12-16
A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component Frontend/Template Management Module. This manipulation caus…
- CVE-2025-2040MEDIUMCVSS 6.3EG 6.32025-03-06
A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation leads to improper neutralization of…
- CVE-2025-23211CRITICALCVSS 9.9EG 9.92025-01-28
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. Th…
- CVE-2025-23376LOWCVSS 2.3EG 2.32025-04-28
Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exp…
- CVE-2025-26789MEDIUMCVSS 6.9EG 0.02025-02-14
An issue was discovered in Logpoint AgentX before 1.5.0. A vulnerability caused by limited access controls allowed li-admin users to access sensitive information about AgentX Manager in a Logpoint deployment.
- CVE-2025-26865LOWCVSS 3.5EG 3.52025-03-10
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18. It's a regression between 18.12.17 and 18.12.18. In case you use som…
- CVE-2025-27516HIGHCVSS 8.8EG 8.82025-03-05
Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a template to execute arbitrary Python code. To e…
- CVE-2025-32461CRITICALCVSS 9.9EG 9.92025-04-09
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.
- CVE-2025-34300CRITICALCVSS 10.0EG 0.02025-07-16
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbit…
- CVE-2025-35113MEDIUMCVSS 5.9EG 5.92025-08-26
Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by loading a specially crafted payload. Users should upgrade to Agiloft Re…
- CVE-2025-37729CRITICALCVSS 9.1EG 9.12025-10-13
Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string …
- CVE-2025-3841LOWCVSS 3.3EG 3.32025-04-21
A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.py of the component Jinja2 Template Handler. The manipulation…
- CVE-2025-40900MEDIUMCVSS 4.6EG 4.62026-05-19
An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular temp…
- CVE-2025-46661CRITICALCVSS 10.0EG 10.02025-04-28
IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template expressions, aka Server-Side Template-Injection. All instances have been patched by the Supp…
- CVE-2025-46699MEDIUMCVSS 4.3EG 4.32026-01-23
Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a Template Engine vulnerability in the Server. A low privileged attacker with remote access could potentially exploit th…
- CVE-2025-46731HIGHCVSS 7.2EG 7.22025-05-05
Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access…
- CVE-2025-47916CRITICALCVSS 10.0EG 10.02025-05-16
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a p…
- CVE-2025-49136CRITICALCVSS 9.0EG 9.02025-06-09
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functions which is enabled by default in Sprig enables capturing of env va…
- CVE-2025-49142HIGHCVSS 7.1EG 0.02025-06-10
Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions prior to 2.4.10 or prior to 1.6.32 are potentially affected. Due to insufficient security configuration of the Jinja2 templating feature …
- CVE-2025-49619HIGHCVSS 8.5EG 8.52025-06-07
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject craft…
- CVE-2025-49828HIGHCVSS 8.8EG 8.82025-07-15
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.4.1 are vulnerable to remote c…
- CVE-2025-52122CRITICALCVSS 9.8EG 9.82025-08-27
Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).
- CVE-2025-5325MEDIUMCVSS 6.3EG 6.32025-05-29
A vulnerability has been found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file…
- CVE-2025-53833CRITICALCVSS 10.0EG 10.02025-07-14
LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could potentially lead to Remote Code Execution…
- CVE-2025-53909CRITICALCVSS 9.1EG 9.12025-07-17
mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notification template system used by mailcow for sending quota an…
- CVE-2025-54287MEDIUMCVSS 6.5EG 6.52025-10-02
Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates us…
- CVE-2025-57811HIGHCVSS 7.2EG 7.22025-08-25
Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to…
- CVE-2025-59340CRITICALCVSS 9.8EG 9.82025-09-17
jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.8.1, by using mapper.getTypeFactory().constructFromCanonical(), it is possible to instruct the underlying ObjectMapper …
- CVE-2025-60355CRITICALCVSS 9.8EG 9.82025-10-28
zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
- CVE-2025-62369HIGHCVSS 7.2EG 7.22025-11-04
Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating functionality, allowing authen…
- CVE-2025-62416MEDIUMCVSS 5.1EG 5.12025-10-16
Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descripti…
- CVE-2025-64087CRITICALCVSS 9.8EG 9.82026-01-20
A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.
- CVE-2025-65106HIGHCVSS 8.3EG 0.02025-11-21
LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access P…
- CVE-2025-6518MEDIUMCVSS 6.3EG 6.32025-06-23
A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the function SingleLLMCallNode of the file backend/pyspur/nodes/llm/single_llm_call.py of the component Jinja2 Template Handler. T…
- CVE-2025-65602CRITICALCVSS 9.8EG 9.82025-12-10
A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.
- CVE-2025-66294HIGHCVSS 8.8EG 8.82025-12-01
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, un…
- CVE-2025-66297HIGHCVSS 8.8EG 8.82025-12-01
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the page frontmatter. By injecting malicious Twig expressions, the …
- CVE-2025-66298HIGHCVSS 7.5EG 7.52025-12-01
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload to exploit a Server-Side Tem…
Map vulnerabilities like CWE-1336 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1336 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →