CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

Parent: CWE-94 - Improper Control of Generation of Code ('Code Injection')

The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

155 vulnerabilities with CWE-1336
CVE-2025-64087 CRITICAL
opensagres XDocReport <2.1.0 - SSTI
CVSS 9.8
CVE-2025-68454 HIGH
Craftcms Craft Cms < 4.16.17 - Remote Code Execution
CVSS 8.8
CVE-2025-68929 CRITICAL
Frappe <14.99.6-15.88.1 - Authenticated RCE
CVSS 9.0
CVE-2025-67843 HIGH
Mintlify Platform <2025-11-15 - SSTI
CVSS 8.3
CVE-2025-14700 CRITICAL
Craftycontrol Crafty Controller - Remote Code Execution
CVSS 9.9
CVE-2025-14731 MEDIUM
CTCMS Content Management System <2.1.2 - XSS
CVSS 6.3
CVE-2025-66438 HIGH
ERPNext <15.89.0 - SSTI
CVSS 8.8
CVE-2025-66437 HIGH
ERPNext <15.89.0 - SSRF
CVSS 8.8
CVE-2025-66436 MEDIUM
Frappe ERPNext <15.89.0 - SSRF
CVSS 4.3
CVE-2025-66435 MEDIUM
Frappe ERPNext <15.89.0 - SSRF
CVSS 4.3
CVE-2025-66434 HIGH
Frappe ERPNext <15.89.0 - SSRF
CVSS 8.8
CVE-2025-65602 CRITICAL
ChanCMS 3.3.4 - Code Injection
CVSS 9.8
CVE-2025-66299 HIGH
Grav <1.8.0-beta.27 - SSRF
CVSS 8.8
CVE-2025-66298 HIGH
Grav <1.8.0-beta.27 - Info Disclosure
CVSS 7.5
CVE-2025-66297 HIGH
Grav <1.8.0-beta.27 - RCE/Privilege Escalation
CVSS 8.8
CVE-2025-66294 HIGH
Grav <1.8.0-beta.27 - SSTI
CVSS 8.8
CVE-2025-66361 MEDIUM
Logpoint <7.7.0 - Info Disclosure
CVSS 6.5
CVE-2025-65106 HIGH
LangChain <1.0.6 - Code Injection
CVE-2025-62369 HIGH
Xibo < 4.3.1 - Remote Code Execution
CVSS 7.2
CVE-2025-60355 CRITICAL
zhangyd-c OneBlog <2.3.9 - Server-Side Template Injection
CVSS 9.8
CVE-2025-62416 MEDIUM
Webkul Bagisto < 2.3.8 - Remote Code Execution
CVSS 5.1
CVE-2025-37729 CRITICAL
Elastic Cloud Enterprise - Info Disclosure
CVSS 9.1
CVE-2025-54287 MEDIUM
Canonical LXD >=4.0 - Info Disclosure
CVSS 6.5
CVE-2025-10380 HIGH
Advanced Views - Server-Side Template Injection
CVSS 8.8
CVE-2025-59340 CRITICAL
Hubspot Jinjava < 2.8.1 - Remote Code Execution
CVSS 9.8
Details
Vulnerabilities 155