CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
193 vulnerabilities with CWE-1336
CVE-2026-44209
HIGH
Banks: Critical Remote Code Execution (RCE) via Jinja2 SSTI
CVSS 7.5
CVE-2026-44723
MEDIUM
Vowpal Wabbit: Shell injection via crafted PR title in python_checks.yml allows arbitrary command execution on CI runner
CVSS 5.0
CVE-2026-9498
MEDIUM
Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in a template engine
CVSS 6.3
CVE-2026-29207
MEDIUM
Apache OFBiz: Low-Privilege SSTI Leading to RCE in the Content Component
CVSS 6.5
CVE-2026-8740
MEDIUM
Sanluan PublicCMS templateResult API TemplateResultDirective.java execute special elements used in a template engine
CVSS 6.3
CVE-2026-45714
CRITICAL
CubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCE
CVSS 9.1
CVE-2026-44377
CRITICAL
CubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCE
CVSS 9.1
CVE-2026-41901
CRITICAL
Thymeleaf: Improper recognition of unauthorized syntax patterns in sandboxed Thymeleaf expressions
CVSS 9.0
CVE-2026-41713
HIGH
VMware Spring AI - Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor
CVSS 8.2
CVE-2026-44129
HIGH
SEPPmail Secure Email Gateway - Server-Side Template Injection
CVE-2026-44916
LOW
Openstack Ironic < 35.0.1 - Improper Neutralization of Special Elements Used in a Template Engine
CVSS 3.0
CVE-2026-42203
HIGH
LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVSS 8.8
CVE-2026-6984
MEDIUM
AstrBotDevs AstrBot Dashboard API t2i.py create_template special elements used in a template engine
CVSS 4.7
CVE-2026-41318
MEDIUM
AnythingLLM < 1.12.1 - Stored DOM XSS in Chart Caption Renderer
CVSS 5.4
CVE-2026-34587
HIGH
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
CVSS 8.1
CVE-2026-40602
MEDIUM
hass-cli: Handling of user-supplied Jinja2 templates
CVSS 5.6
CVE-2026-40478
CRITICAL
Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
CVSS 9.0
CVE-2026-40477
CRITICAL
Improper restriction of the scope of accessible objects in Thymeleaf expressions
CVSS 9.0
CVE-2026-40320
HIGH
Giskard ConformityCheck - Unsandboxed Jinja2 Template Rendering
CVSS 7.8
CVE-2026-33392
HIGH
JetBrains YouTrack <2025.3.131383 - RCE
CVSS 7.2
CVE-2026-5987
MEDIUM
Sanluan PublicCMS FreeMarker Template AbstractFreemarkerView.java AbstractFreemarkerView.doRender special elements used in a template engine
CVSS 4.7
CVE-2026-40087
MEDIUM
LangChain has incomplete f-string validation in prompt templates
CVSS 5.3
CVE-2026-39980
CRITICAL
OpenCTI affected by RCE via notifier template
CVSS 9.1
CVE-2026-35477
MEDIUM
InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escape
CVSS 5.5
CVE-2026-34724
HIGH
Zammad AI Agent - Server-Side Template Injection
CVSS 7.2
Details
Vulnerabilities
193