CWE-1336
CVEs classified under CWE-1336, newest first.
79 CVEsRSS
GHSA-vwf3-4xxj-qg6hHighmcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
CVE-2026-59989CriticalPhalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
CVE-2026-62682CriticalOrval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in servers[0].url is emitted into request URL template literals generated when output.baseUr…
CVE-2026-62681CriticalOrval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch,…
CVE-2026-71868CriticalOrval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum default is emitted into a module-level template literal emitted by zod …
CVE-2026-71871CriticalOrval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header parameter default is emitted into a module-level template literal emit…
CVE-2026-71869CriticalOrval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an array item default is emitted into a module-level template literal emitted b…
CVE-2026-72717CriticalOrval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-level template literal emitted by zod…
CVE-2026-72716CriticalOrval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a query parameter default is emitted into a module-level template literal emitt…
CVE-2026-75979Medium· 6.3A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta
A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sq…
CVE-2026-53964High· 7.2Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
CVE-2026-52889Critical· 9.8Formie is a Craft CMS plugin for creating forms
Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Valu…
CVE-2026-75829High· 8.1grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled
grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and cont…
CVE-2026-65974Critical· 9.9ERPNext is a free and open source Enterprise Resource Planning tool
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without fo…
CVE-2026-44845Medium· 6.7JumpServer is an open source bastion host and an operation and maintenance security audit system
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into …
CVE-2026-19929Medium· 6.3A vulnerability was identified in OpenBoxes up to 0.9.6
A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Template Processing. The manipulat…
CVE-2026-72827High· 8.8Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands
Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject Twig payloads using th…
CVE-2026-46439High· 7.8compliance-trestle is a tooling platform for managing compliance as code
compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively…
CVE-2022-4993Critical· 9.1HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notatio…
HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notatio…
CVE-2026-73505High· 7.8Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose functi…
CVE-2026-73299Critical· 10.0Prompty is a markdown file format (.prompty) for LLM prompts
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controll…
CVE-2026-69118High· 8.8Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade direc…
CVE-2026-72911Critical· 9.9ERPNext is a free and open source Enterprise Resource Planning tool
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.p…
CVE-2026-71502NoneCTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conv…
CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conv…
GHSA-xrmj-5g4g-8987Medium· 4.2@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
CVE-2026-54662High· 8.3swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
CVE-2026-54661High· 8.3swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
CVE-2026-54664High· 8.3swagger-typescript-api vulnerable to code injection via unescaped enum string values
swagger-typescript-api vulnerable to code injection via unescaped enum string values
CVE-2026-54666High· 8.3swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
CVE-2026-54653High· 8.8`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field