CWE-1336
CVEs classified under CWE-1336, newest first.
79 CVEsRSS
CVE-2026-54654High· 7.8`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
CVE-2026-54621High· 7.8`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
GHSA-6xj8-qv9j-xcjqHigh· 7.8Oh My Posh: Arbitrary command execution via template injection in the path segment
Oh My Posh: Arbitrary command execution via template injection in the path segment
GHSA-w28w-gp39-m4p6Critical· 10.0Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
CVE-2026-63728Medium· 6.3PoCGitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature
Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Spri…
CVE-2026-9558Critical· 9.9PoCMautic has Server-Side Template Injection (SSTI) in Theme Templates
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
CVE-2026-39379High· 7.1GeoNetwork has reflected XSS through client-side template injection
GeoNetwork has reflected XSS through client-side template injection
CVE-2026-52796Low· 3.5Gogs has DoS in rendering issue index pattern
Gogs has DoS in rendering issue index pattern
CVE-2026-11407High· 7.2Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
CVE-2026-40478Critical· 9.0Thymeleaf is a server-side Java template engine for web and standalone environments
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mecha…
CVE-2026-40477Critical· 9.0PoCThymeleaf is a server-side Java template engine for web and standalone environments
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanism…
CVE-2026-34202High· 7.5ZEBRA is a Zcash node written entirely in Rust
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic…
CVE-2026-22244High· 7.2OpenMetadata is a unified metadata platform
OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges t…
CVE-2025-66299High· 8.8Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypas…
CVE-2025-66298High· 7.5Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload to exploit a Server-Side T…
CVE-2025-66297High· 8.8Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the page frontmatter. By injecting malicious Twig expressions, th…
CVE-2025-66294High· 8.8PoCGrav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, …
CVE-2025-27516Medium· 7.3Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
CVE-2024-23692Critical· 9.8CISA KEVPoCRejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending…