VulnSea

CWE-1336

CVEs classified under CWE-1336, newest first.

79 CVEsRSS

GHSA-vwf3-4xxj-qg6hHigh
1mo ago

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

▾ Twilightmcp-contextforge-gateway · mcp-contextforge-gatewayvia GHSA
CVE-2026-59989Critical
1mo ago

Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)

Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)

▾ Midnightphalcon · phalcon/cphalconEPSS 0.54%via GHSA
CVE-2026-62682Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in servers[0].url is emitted into request URL template literals generated when output.baseUr…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-62681Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch,…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71868Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum default is emitted into a module-level template literal emitted by zod …

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71871Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header parameter default is emitted into a module-level template literal emit…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71869Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an array item default is emitted into a module-level template literal emitted b…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-72717Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-level template literal emitted by zod…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-72716Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a query parameter default is emitted into a module-level template literal emitt…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-75979Medium· 6.3
1mo ago

A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta

A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sq…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-53964High· 7.2
1mo ago

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

▾ Twilightdocument-merge-service · document-merge-servicevia OSV
CVE-2026-52889Critical· 9.8
1mo ago

Formie is a Craft CMS plugin for creating forms

Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Valu…

▾ Midnightverbb · verbb/formieEPSS 1.3%via NVD
CVE-2026-75829High· 8.1
1mo ago

grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled

grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and cont…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-65974Critical· 9.9
1mo ago

ERPNext is a free and open source Enterprise Resource Planning tool

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without fo…

▾ Midnightfrappe · erpnextEPSS 1.0%via NVD
CVE-2026-44845Medium· 6.7
1mo ago

JumpServer is an open source bastion host and an operation and maintenance security audit system

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into …

▾ SunlitEPSS 0.73%via NVD
CVE-2026-19929Medium· 6.3
1mo ago

A vulnerability was identified in OpenBoxes up to 0.9.6

A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Template Processing. The manipulat…

▾ SunlitEPSS 0.50%via NVD
CVE-2026-72827High· 8.8
1mo ago

Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands

Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject Twig payloads using th…

▾ TwilightEPSS 0.85%via NVD
CVE-2026-46439High· 7.8
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.27%via NVD
CVE-2022-4993Critical· 9.1
1mo ago

HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notatio…

HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notatio…

▾ MidnightEPSS 0.63%via NVD
CVE-2026-73505High· 7.8
1mo ago

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose functi…

▾ Twilightjandedobbeleer · github.com/jandedobbeleer/oh-my-poshEPSS 0.21%via NVD
CVE-2026-73299Critical· 10.0
1mo ago

Prompty is a markdown file format (.prompty) for LLM prompts

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controll…

▾ Midnightmicrosoft · promptyEPSS 1.8%via NVD
CVE-2026-69118High· 8.8
1mo ago

Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code

Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade direc…

▾ TwilightEPSS 0.80%via NVD
CVE-2026-72911Critical· 9.9
1mo ago

ERPNext is a free and open source Enterprise Resource Planning tool

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.p…

▾ MidnightEPSS 0.72%via NVD
CVE-2026-71502None
1mo ago

CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conv…

CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conv…

▾ SunlitEPSS 0.74%via NVD
GHSA-xrmj-5g4g-8987Medium· 4.2
1mo ago

@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

▾ Sunlitdynatrace-oss · @dynatrace-oss/dynatrace-mcp-servervia GHSA
CVE-2026-54662High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54661High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54664High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped enum string values

swagger-typescript-api vulnerable to code injection via unescaped enum string values

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54666High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54653High· 8.8
2mo ago

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.71%via OSV
CWE-1336 vulnerabilities (CVEs) — page 2 · VulnSea