CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
193 vulnerabilities with CWE-1336
CVE-2025-49619
HIGH
Skyvern SSTI Remote Code Execution
CVSS 8.5
CVE-2025-5325
MEDIUM
zhilink ADP Application Developer Platform <1.0.0 - XSS
CVSS 6.3
CVE-2025-47916
CRITICAL
Invisioncommunity < 5.0.7 - Remote Code Execution
CVSS 10.0
CVE-2025-46731
HIGH
Craft CMS <4.14.13, <5.6.16 - Authenticated RCE
CVSS 7.2
CVE-2025-23376
LOW
Dell PowerProtect Data Manager 19.16-19.18 - Information Disclosure via Template Injection
CVSS 2.3
CVE-2025-46661
CRITICAL
IPW Systems Metazo < 8.1.13 - Unauthenticated Remote Code Execution via Smarty Template Injection
CVSS 10.0
CVE-2025-3841
LOW
wix-incubator jam <e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9 - Impro...
CVSS 3.3
CVE-2025-32461
CRITICAL
Tiki < 21.12, 22-24.7, 25-27.1, 28-28.2 - Remote Code Execution via wikiplugin_includetpl Eval
CVSS 9.9
CVE-2025-1040
HIGH
AutoGPT < 0.4.0 - Server-Side Template Injection via AgentOutputBlock Format String
CVSS 8.8
CVE-2025-26865
LOW
Apache OFBiz <18.12.18 - Info Disclosure
CVSS 3.5
CVE-2025-2040
MEDIUM
zhijiantianya ruoyi-vue-pro 2.4.1 - XSS
CVSS 6.3
CVE-2025-27516
HIGH
Jinja < 3.1.6 - Remote Code Execution via |attr Filter Sandbox Bypass
CVSS 8.8
CVE-2025-26789
MEDIUM
Logpoint AgentX <1.5.0 - Info Disclosure
CVE-2025-23211
CRITICAL
Tandoor Recipes < 1.5.24 - Authenticated Server-Side Template Injection via Jinja2
CVSS 9.9
CVE-2024-58303
HIGH
FoF Pretty Mail 1.1.2 - Code Injection
CVE-2024-58293
HIGH
Akaunting 3.1.8 - Authenticated Server-Side Template Injection via Form Input Fields
CVE-2024-8238
HIGH
Aim < 3.22.0 AimQL str.format_map - RestrictedPython Code Execution
CVSS 8.1
CVE-2024-9150
HIGH
Wyn Enterprise <8.0.00204.0 - Code Injection
CVE-2024-57177
HIGH
perfood/couch-auth <= 0.21.2 - SSRF
CVSS 7.3
CVE-2024-54954
HIGH
OneBlog < 2.3.6 - Template Injection via Template Management
CVSS 8.0
CVE-2024-12583
CRITICAL
Dynamics 365 Integration plugin - RCE
CVSS 9.9
CVE-2024-56326
HIGH
Jinja < 3.1.5 - Remote Code Execution via Sandboxed Template String Format Bypass
CVSS 7.8
CVE-2024-55660
CRITICAL
SiYuan < 3.1.16 - Server-Side Template Injection via Sprig Template Engine
CVSS 9.8
CVE-2024-55652
MEDIUM
PenDoc <1d4219c596f4f518798492e48386a20c6 - Code Injection
CVSS 6.5
CVE-2024-30372
MEDIUM
Allegra < 7.5.1 - Authenticated Remote Code Execution via getLinkText Template Injection
CVSS 6.3
Details
Vulnerabilities
193