CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

Parent: CWE-94 - Improper Control of Generation of Code ('Code Injection')

The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

193 vulnerabilities with CWE-1336
CVE-2025-66299 HIGH
Grav < 1.8.0-beta.27 - Authenticated Server-Side Template Injection via Twig Directive Manipulation
CVSS 8.8
CVE-2025-66298 HIGH
Grav <1.8.0-beta.27 - Info Disclosure
CVSS 7.5
CVE-2025-66297 HIGH
Grav <1.8.0-beta.27 - RCE/Privilege Escalation
CVSS 8.8
CVE-2025-66294 HIGH
Grav < 1.8.0-beta.27 - Server-Side Template Injection via Weak Twig Validation
CVSS 8.8
CVE-2025-66361 MEDIUM
Logpoint SIEM < 7.7.0 - Sensitive Information Exposure in System Processes
CVSS 6.5
CVE-2025-65106 HIGH
langchain-core 1.0.0-1.0.6 - Template Injection via Untrusted Template Strings
CVE-2025-62369 HIGH
Xibo 4.1.0-4.3.0 - Authenticated Remote Code Execution via CMS Developer Module Templating
CVSS 7.2
CVE-2025-60355 CRITICAL
zhangyd-c OneBlog <2.3.9 - Server-Side Template Injection
CVSS 9.8
CVE-2025-62416 MEDIUM
Bagisto < 2.3.8 - Authenticated Server-Side Template Injection in Product Description Renderer
CVSS 5.1
CVE-2025-37729 CRITICAL
Elastic Cloud Enterprise - Info Disclosure
CVSS 9.1
CVE-2025-54287 MEDIUM
Canonical LXD >=4.0 - Info Disclosure
CVSS 6.5
CVE-2025-10380 HIGH
Advanced Views - Server-Side Template Injection
CVSS 8.8
CVE-2025-59340 CRITICAL
jinjava < 2.8.1 - Remote Code Execution via ObjectMapper Deserialization
CVSS 9.8
CVE-2025-52122 CRITICAL
Freeform 5.0.0-5.10.15 - Server-Side Template Injection via Form Submission Title
CVSS 9.8
CVE-2025-35113 MEDIUM
Agiloft 19-28 - Authenticated Remote Code Execution via EUI Template Injection
CVSS 5.9
CVE-2025-57811 HIGH
Craft CMS 4.0.0-RC1-4.16.5 and 5.0.0-RC1-5.8.6 - Remote Code Execution via Twig SSTI
CVSS 7.2
CVE-2025-9094 MEDIUM
ThingsBoard 4.1 - Server-Side Template Injection in Add Gateway Handler
CVSS 4.3
CVE-2025-53909 CRITICAL
mailcow: dockerized <2025-07 - SSTI
CVSS 9.1
CVE-2025-34300 CRITICAL
Template Injection Vulnerability in Sawtooth Software
CVE-2025-49828 HIGH
Conjur 1.19.5-1.21.1 and 13.1-13.4.1 - Authenticated Remote Code Execution via Template Injection
CVSS 8.8
CVE-2025-53833 CRITICAL
LaRecipe < 2.8.1 - Server-Side Template Injection
CVSS 10.0
CVE-2025-6761 HIGH
Kingdee Cloud-Starry-Sky Enterprise Edition - XSS
CVSS 7.3
CVE-2025-6518 MEDIUM
PySpur-Dev <0.1.18 - Improper Neutralization
CVSS 6.3
CVE-2025-49142 HIGH
Nautobot <2.4.10-1.6.32 - Code Injection
CVSS 7.1
CVE-2025-49136 CRITICAL
listmonk 4.0.0-5.0.1 - Unauthenticated Sensitive Environment Variable Exposure via Template Function
CVSS 9.0
Details
Vulnerabilities 193