CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

Parent: CWE-94 - Improper Control of Generation of Code ('Code Injection')

The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

175 vulnerabilities with CWE-1336
CVE-2026-40320 HIGH
Giskard ConformityCheck - Unsandboxed Jinja2 Template Rendering
CVSS 7.8
CVE-2026-33392 HIGH
JetBrains YouTrack <2025.3.131383 - RCE
CVSS 7.2
CVE-2026-5987 MEDIUM
Sanluan PublicCMS FreeMarker Template AbstractFreemarkerView.java AbstractFreemarkerView.doRender special elements used in a template engine
CVSS 4.7
CVE-2026-40087 MEDIUM
LangChain has incomplete f-string validation in prompt templates
CVSS 5.3
CVE-2026-39980 CRITICAL
OpenCTI affected by RCE via notifier template
CVSS 9.1
CVE-2026-35477 MEDIUM
InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escape
CVSS 5.5
CVE-2026-34724 HIGH
Zammad AI Agent - Server-Side Template Injection
CVSS 7.2
CVE-2026-35044 HIGH
BentoML <1.4.38 Dockerfile Generation - Server-Side Template Injection
CVSS 8.8
CVE-2026-26026 CRITICAL
GLPI 11.0.0-11.0.5 Templates - Admin Remote Code Execution
CVSS 9.1
CVE-2026-5559 MEDIUM
AntaresMugisho PyBlade AST Validation sandbox.py _is_safe_ast special elements used in a template engine
CVSS 6.3
CVE-2026-28797 HIGH
RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component
CVSS 8.8
CVE-2026-34202 HIGH
Zebra node crash — V5 transaction hash panic (P2P reachable)
CVSS 7.5
CVE-2026-34172 HIGH
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
CVSS 8.8
CVE-2026-28228 HIGH
OpenOLAT: Server-Side Template Injection (SSTI) in Velocity templates allows Remote Code Execution
CVSS 8.8
CVE-2026-33654 CRITICAL
Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling
CVSS 9.8
CVE-2026-33897 CRITICAL
Incus vulnerable to arbitrary file read and write through pongo templates
CVSS 9.9
CVE-2026-33154 HIGH
dynaconf Affected by Remote Code Execution (RCE) via Insecure Template Evaluation in @jinja Resolver
CVSS 7.5
CVE-2026-33130 MEDIUM
Uptime Kuma: SSTI in Notification Templates Allows Arbitrary File Read (Incomplete Fix for GHSA-vffh-c9pq-4crh)
CVSS 6.5
CVE-2026-32261 HIGH
RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin
CVE-2026-31864 MEDIUM
JumpServer - Server-Side Template Injection
CVSS 6.8
CVE-2026-22191 MEDIUM
wpDiscuz <7.6.47 - Code Injection
CVSS 5.2
CVE-2026-3725 MEDIUM
1024-lab SmartAdmin <=3.29 - Code Injection
CVSS 6.3
CVE-2026-3714 MEDIUM
OpenCart 4.0.2.3 - Server-Side Template Injection in admin/controller/design/template.php Save Function
CVSS 4.7
CVE-2026-28784 HIGH
Craft CMS 4.0.0-4.16.18 - Authenticated Remote Code Execution via Twig Map Filter
CVSS 7.2
CVE-2026-28783 CRITICAL
Craft CMS <5.9.0-beta.1/4.17.0-beta.1 - RCE
CVSS 9.1
Details
Vulnerabilities 175