VulnSea

CWE-1336

CVEs classified under CWE-1336, newest first.

79 CVEsRSS

CVE-2026-54654High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via OSV
CVE-2026-54621High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via OSV
GHSA-6xj8-qv9j-xcjqHigh· 7.8
2mo ago

Oh My Posh: Arbitrary command execution via template injection in the path segment

Oh My Posh: Arbitrary command execution via template injection in the path segment

▾ Twilightjandedobbeleer · github.com/jandedobbeleer/oh-my-poshvia GHSA
GHSA-w28w-gp39-m4p6Critical· 10.0
2mo ago

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

▾ Midnightprompty · @prompty/corevia GHSA
CVE-2026-63728Medium· 6.3PoC
2mo ago

Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature

Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Spri…

▾ Twilightgitleaks · gitleaksEPSS 0.21%via CVEORG
CVE-2026-9558Critical· 9.9PoC
2mo ago

Mautic has Server-Side Template Injection (SSTI) in Theme Templates

Mautic has Server-Side Template Injection (SSTI) in Theme Templates

▾ Abyssalmautic · mautic/coreEPSS 0.79%via GHSA
CVE-2026-39379High· 7.1
2mo ago

GeoNetwork has reflected XSS through client-side template injection

GeoNetwork has reflected XSS through client-side template injection

▾ Twilightgeonetwork-opensource · org.geonetwork-opensource:geonetworkvia GHSA
CVE-2026-52796Low· 3.5
3mo ago

Gogs has DoS in rendering issue index pattern

Gogs has DoS in rendering issue index pattern

▾ Sunlitgogs · gogs.io/gogsEPSS 0.28%via GHSA
CVE-2026-11407High· 7.2
3mo ago

Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed

Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed

▾ Twilightpimcore · pimcore/pimcoreEPSS 0.62%via GHSA
CVE-2026-40478Critical· 9.0
5mo ago

Thymeleaf is a server-side Java template engine for web and standalone environments

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mecha…

▾ Midnightthymeleaf · thymeleafEPSS 1.2%via NVD
CVE-2026-40477Critical· 9.0PoC
5mo ago

Thymeleaf is a server-side Java template engine for web and standalone environments

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanism…

▾ Abyssalthymeleaf · thymeleafEPSS 0.94%via NVD
CVE-2026-34202High· 7.5
6mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic…

▾ Twilightzfnd · zebraEPSS 0.93%via NVD
CVE-2026-22244High· 7.2
8mo ago

OpenMetadata is a unified metadata platform

OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges t…

▾ Twilightopen-metadata · openmetadataEPSS 1.3%via NVD
CVE-2025-66299High· 8.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypas…

▾ Twilightgetgrav · gravEPSS 0.60%via NVD
CVE-2025-66298High· 7.5
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload to exploit a Server-Side T…

▾ Twilightgetgrav · gravEPSS 0.38%via NVD
CVE-2025-66297High· 8.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the page frontmatter. By injecting malicious Twig expressions, th…

▾ Twilightgetgrav · gravEPSS 0.78%via NVD
CVE-2025-66294High· 8.8PoC
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, …

▾ Midnightgetgrav · gravEPSS 2.8%via NVD
CVE-2025-27516Medium· 7.3
1y ago

Jinja2 vulnerable to sandbox breakout through attr filter selecting format method

Jinja2 vulnerable to sandbox breakout through attr filter selecting format method

▾ Sunlitjinja2 · jinja2EPSS 0.50%via OSV
CVE-2024-23692Critical· 9.8CISA KEVPoC
2y ago

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending…

▾ Hadalrejetto · http_file_serverEPSS 99%via NVD
CWE-1336 vulnerabilities (CVEs) — page 3 · VulnSea