VulnSea

CWE-1336

CVEs classified under CWE-1336, newest first.

69 CVEsRSS

CVE-2026-94109High· 8.8
2d ago

openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration

openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expres…

Twilightopenequella · openEQUELLAEPSS 0.92%via NVD
CVE-2026-61453Medium
6d ago

Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

Sunlitgetgrav · getgrav/gravEPSS 0.16%via GHSA
CVE-2026-92592High· 8.8
6d ago

Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bou…

Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bou…

Twilightcraftcms · cmsEPSS 0.50%via NVD
CVE-2026-88064High· 8.8
6d ago

Backstage is an open framework for building developer portals

Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied by an authenticated user who can regist…

Twilightbackstage · backstageEPSS 0.63%via NVD
CVE-2026-91925High· 8.8PoC
1w ago

Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code

Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 paylo…

Midnightpolyaxon · polyaxonEPSS 0.48%via NVD
CVE-2026-9160Medium· 4.3
1w ago

CSTI in Arma Digital's Website Template

Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted…

SunlitArma Digital Media Inc. · Website TemplateEPSS 0.16%via CVEORG
CVE-2026-81910Medium· 6.5
1w ago

Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values

Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyl…

Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-89094Critical· 9.9
1w ago

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

MidnightForgejo · ForgejoEPSS 0.50%via NVD
CVE-2026-19584High· 7.7
1w ago

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a mali…

TwilightRapid7 · VelociraptorEPSS 0.19%via NVD
CVE-2026-87021High· 7.2
1w ago

Tanium addressed an unauthorized code execution vulnerability in Comply.

Tanium addressed an unauthorized code execution vulnerability in Comply.

Twilighttanium · complyEPSS 0.37%via NVD
CVE-2026-33387Medium· 4.6
2w ago

A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter

A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload,…

SunlitNozomi Networks · GuardianEPSS 0.18%via NVD
CVE-2026-75650Critical· 10.0CISA KEV0dayPoC
2w ago

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnera…

Hadaladobe · commerceEPSS 2.1%via NVD
CVE-2026-52762High· 7.1PoC
2w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic template feature that can be escalated to confirmed Remote Code Executio…

MidnightYesWiki · yeswikiEPSS 0.45%via NVD
CVE-2026-46636High· 8.7
2w ago

Twig is a template language for PHP

Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inher…

Twilighttwigphp · TwigEPSS 0.36%via NVD
CVE-2026-85654High· 7.8
2w ago

Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the ge…

Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the ge…

TwilightEPSS 0.14%via NVD
CVE-2026-13297High· 7.5
2w ago

IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.

IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.

TwilightIBM · Verify Identity AccessEPSS 0.25%via NVD
CVE-2026-75036None
2w ago

A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster

A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repo…

SunlitEPSS 0.21%via NVD
CVE-2026-72807High· 8.0
2w ago

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.20%via GHSA
CVE-2026-12894High· 8.8
3w ago

A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails

A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails…

TwilightQuarkus · io.quarkus:quarkus-quteEPSS 0.37%via NVD
CVE-2026-82447High· 8.8
3w ago

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja te…

TwilightEPSS 0.45%via NVD
CVE-2026-77939Medium· 6.5
3w ago

Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony Expressi…

Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony Expressi…

SunlitEPSS 0.44%via NVD
CVE-2026-55559Critical· 9.8
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templat…

Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.55%via NVD
CVE-2026-37004Critical· 9.8
3w ago

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

Midnightlitellm · litellmEPSS 0.55%via OSV
CVE-2026-47727None
3w ago

Trilium is an open-source hierarchical note-taking application

Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the default-on "Safe import" filter fails to neutralize the shareTemplate relation because that relation is not marked as dangerous, allowing a…

SunlitEPSS 0.43%via NVD
CVE-2026-54718High· 7.2
3w ago

Silverstripe Advanced Workflow is a highly configurable step-based workflow module

Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side te…

Twilightsymbiote · symbiote/silverstripe-advancedworkflowEPSS 0.72%via NVD
CVE-2026-57170High· 7.8
3w ago

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-par…

TwilightEPSS 0.20%via NVD
GHSA-vwf3-4xxj-qg6hHigh
4w ago

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

Twilightmcp-contextforge-gateway · mcp-contextforge-gatewayvia GHSA
CVE-2026-59989Critical
1mo ago

Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)

Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)

Midnightphalcon · phalcon/cphalconEPSS 0.31%via GHSA
CVE-2026-62682Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in servers[0].url is emitted into request URL template literals generated when output.baseUr…

Midnightorval · orvalEPSS 0.62%via NVD
CVE-2026-62681Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch,…

Midnightorval · orvalEPSS 0.66%via NVD
CWE-1336 vulnerabilities (CVEs) · VulnSea