CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
193 vulnerabilities with CWE-1336
CVE-2025-66299
HIGH
Grav < 1.8.0-beta.27 - Authenticated Server-Side Template Injection via Twig Directive Manipulation
CVSS 8.8
CVE-2025-66298
HIGH
Grav <1.8.0-beta.27 - Info Disclosure
CVSS 7.5
CVE-2025-66297
HIGH
Grav <1.8.0-beta.27 - RCE/Privilege Escalation
CVSS 8.8
CVE-2025-66294
HIGH
Grav < 1.8.0-beta.27 - Server-Side Template Injection via Weak Twig Validation
CVSS 8.8
CVE-2025-66361
MEDIUM
Logpoint SIEM < 7.7.0 - Sensitive Information Exposure in System Processes
CVSS 6.5
CVE-2025-65106
HIGH
langchain-core 1.0.0-1.0.6 - Template Injection via Untrusted Template Strings
CVE-2025-62369
HIGH
Xibo 4.1.0-4.3.0 - Authenticated Remote Code Execution via CMS Developer Module Templating
CVSS 7.2
CVE-2025-60355
CRITICAL
zhangyd-c OneBlog <2.3.9 - Server-Side Template Injection
CVSS 9.8
CVE-2025-62416
MEDIUM
Bagisto < 2.3.8 - Authenticated Server-Side Template Injection in Product Description Renderer
CVSS 5.1
CVE-2025-37729
CRITICAL
Elastic Cloud Enterprise - Info Disclosure
CVSS 9.1
CVE-2025-54287
MEDIUM
Canonical LXD >=4.0 - Info Disclosure
CVSS 6.5
CVE-2025-10380
HIGH
Advanced Views - Server-Side Template Injection
CVSS 8.8
CVE-2025-59340
CRITICAL
jinjava < 2.8.1 - Remote Code Execution via ObjectMapper Deserialization
CVSS 9.8
CVE-2025-52122
CRITICAL
Freeform 5.0.0-5.10.15 - Server-Side Template Injection via Form Submission Title
CVSS 9.8
CVE-2025-35113
MEDIUM
Agiloft 19-28 - Authenticated Remote Code Execution via EUI Template Injection
CVSS 5.9
CVE-2025-57811
HIGH
Craft CMS 4.0.0-RC1-4.16.5 and 5.0.0-RC1-5.8.6 - Remote Code Execution via Twig SSTI
CVSS 7.2
CVE-2025-9094
MEDIUM
ThingsBoard 4.1 - Server-Side Template Injection in Add Gateway Handler
CVSS 4.3
CVE-2025-53909
CRITICAL
mailcow: dockerized <2025-07 - SSTI
CVSS 9.1
CVE-2025-34300
CRITICAL
Template Injection Vulnerability in Sawtooth Software
CVE-2025-49828
HIGH
Conjur 1.19.5-1.21.1 and 13.1-13.4.1 - Authenticated Remote Code Execution via Template Injection
CVSS 8.8
CVE-2025-53833
CRITICAL
LaRecipe < 2.8.1 - Server-Side Template Injection
CVSS 10.0
CVE-2025-6761
HIGH
Kingdee Cloud-Starry-Sky Enterprise Edition - XSS
CVSS 7.3
CVE-2025-6518
MEDIUM
PySpur-Dev <0.1.18 - Improper Neutralization
CVSS 6.3
CVE-2025-49142
HIGH
Nautobot <2.4.10-1.6.32 - Code Injection
CVSS 7.1
CVE-2025-49136
CRITICAL
listmonk 4.0.0-5.0.1 - Unauthenticated Sensitive Environment Variable Exposure via Template Function
CVSS 9.0
Details
Vulnerabilities
193