CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
175 vulnerabilities with CWE-1336
CVE-2024-57177
HIGH
perfood/couch-auth <= 0.21.2 - SSRF
CVSS 7.3
CVE-2024-54954
HIGH
OneBlog < 2.3.6 - Template Injection via Template Management
CVSS 8.0
CVE-2024-12583
CRITICAL
Dynamics 365 Integration plugin - RCE
CVSS 9.9
CVE-2024-56326
HIGH
Jinja < 3.1.5 - Remote Code Execution via Sandboxed Template String Format Bypass
CVSS 7.8
CVE-2024-55660
CRITICAL
SiYuan < 3.1.16 - Server-Side Template Injection via Sprig Template Engine
CVSS 9.8
CVE-2024-55652
MEDIUM
PenDoc <1d4219c596f4f518798492e48386a20c6 - Code Injection
CVSS 6.5
CVE-2024-30372
MEDIUM
Allegra < 7.5.1 - Authenticated Remote Code Execution via getLinkText Template Injection
CVSS 6.3
CVE-2024-48962
HIGH
Apache OFBiz < 18.12.17 - Cross-Site Request Forgery
CVSS 8.8
CVE-2024-39766
HIGH
Intel(R) Neural Compressor <v3.0 - Privilege Escalation
CVSS 7.0
CVE-2024-46366
HIGH
Webkul Krayin CRM 1.3.0 - Client-side Template Injection via Lead Creation
CVSS 8.8
CVE-2024-45053
CRITICAL
Fides 2.19.0-2.44.0 - Authenticated Remote Code Execution via Email Template Injection
CVSS 9.1
CVE-2024-6386
CRITICAL
WPML < 4.6.13 - Authenticated Remote Code Execution via Twig Server-Side Template Injection
CVSS 9.9
CVE-2024-42356
HIGH
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3
CVE-2024-42355
HIGH
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3
CVE-2024-41950
HIGH
Haystack < 2.3.1 - Remote Code Execution via Jinja2 Template Injection
CVSS 7.5
CVE-2024-38363
HIGH
Airbyte < 0.62.2 - Authenticated Remote Code Execution via Server-Side Template Injection
CVSS 8.5
CVE-2024-37621
HIGH
StrongShop 1.0 - Server-Side Template Injection in /shippingOptionConfig/index.blade.php
CVSS 7.2
CVE-2024-37301
HIGH
document-merge-service <= 6.5.1 - Remote Code Execution via Server-Side Template Injection
CVSS 7.2
CVE-2024-23692
CRITICAL
KEV
Rejetto HTTP File Server - Template injection
CVSS 9.8
CVE-2024-34710
HIGH
Wiki.js <= 2.5.302 - Stored Cross-Site Scripting via Invalid HTML Tag Injection
CVSS 7.1
CVE-2024-35191
MEDIUM
Formie < 2.0.44 and 2.1.0-2.1.5 - Authenticated Server-Side Template Injection via Submission Title or Success Message
CVSS 4.4
CVE-2024-32406
HIGH
inducer relate < 2024.1 - Server-Side Template Injection via Batch-Issue Exam Tickets Function
CVSS 7.5
CVE-2024-32651
CRITICAL
changedetection.io <=0.45.20 - Remote Command Execution via Jinja2 SSTI
CVSS 10.0
CVE-2024-25624
MEDIUM
IRIS <2.4.6 - Authenticated Remote Code Execution via Report Template SSTI
CVSS 6.8
CVE-2024-4040
CRITICAL
KEV
CrushFTP < 10.7.1 - Unauthenticated Server-Side Template Injection
CVSS 9.8
Details
Vulnerabilities
175