CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
175 vulnerabilities with CWE-1336
CVE-2026-40320
HIGH
Giskard ConformityCheck - Unsandboxed Jinja2 Template Rendering
CVSS 7.8
CVE-2026-33392
HIGH
JetBrains YouTrack <2025.3.131383 - RCE
CVSS 7.2
CVE-2026-5987
MEDIUM
Sanluan PublicCMS FreeMarker Template AbstractFreemarkerView.java AbstractFreemarkerView.doRender special elements used in a template engine
CVSS 4.7
CVE-2026-40087
MEDIUM
LangChain has incomplete f-string validation in prompt templates
CVSS 5.3
CVE-2026-39980
CRITICAL
OpenCTI affected by RCE via notifier template
CVSS 9.1
CVE-2026-35477
MEDIUM
InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escape
CVSS 5.5
CVE-2026-34724
HIGH
Zammad AI Agent - Server-Side Template Injection
CVSS 7.2
CVE-2026-35044
HIGH
BentoML <1.4.38 Dockerfile Generation - Server-Side Template Injection
CVSS 8.8
CVE-2026-26026
CRITICAL
GLPI 11.0.0-11.0.5 Templates - Admin Remote Code Execution
CVSS 9.1
CVE-2026-5559
MEDIUM
AntaresMugisho PyBlade AST Validation sandbox.py _is_safe_ast special elements used in a template engine
CVSS 6.3
CVE-2026-28797
HIGH
RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component
CVSS 8.8
CVE-2026-34202
HIGH
Zebra node crash — V5 transaction hash panic (P2P reachable)
CVSS 7.5
CVE-2026-34172
HIGH
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
CVSS 8.8
CVE-2026-28228
HIGH
OpenOLAT: Server-Side Template Injection (SSTI) in Velocity templates allows Remote Code Execution
CVSS 8.8
CVE-2026-33654
CRITICAL
Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling
CVSS 9.8
CVE-2026-33897
CRITICAL
Incus vulnerable to arbitrary file read and write through pongo templates
CVSS 9.9
CVE-2026-33154
HIGH
dynaconf Affected by Remote Code Execution (RCE) via Insecure Template Evaluation in @jinja Resolver
CVSS 7.5
CVE-2026-33130
MEDIUM
Uptime Kuma: SSTI in Notification Templates Allows Arbitrary File Read (Incomplete Fix for GHSA-vffh-c9pq-4crh)
CVSS 6.5
CVE-2026-32261
HIGH
RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin
CVE-2026-31864
MEDIUM
JumpServer - Server-Side Template Injection
CVSS 6.8
CVE-2026-22191
MEDIUM
wpDiscuz <7.6.47 - Code Injection
CVSS 5.2
CVE-2026-3725
MEDIUM
1024-lab SmartAdmin <=3.29 - Code Injection
CVSS 6.3
CVE-2026-3714
MEDIUM
OpenCart 4.0.2.3 - Server-Side Template Injection in admin/controller/design/template.php Save Function
CVSS 4.7
CVE-2026-28784
HIGH
Craft CMS 4.0.0-4.16.18 - Authenticated Remote Code Execution via Twig Map Filter
CVSS 7.2
CVE-2026-28783
CRITICAL
Craft CMS <5.9.0-beta.1/4.17.0-beta.1 - RCE
CVSS 9.1
Details
Vulnerabilities
175