CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

Parent: CWE-94 - Improper Control of Generation of Code ('Code Injection')

The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

193 vulnerabilities with CWE-1336
CVE-2024-48962 HIGH
Apache OFBiz < 18.12.17 - Cross-Site Request Forgery
CVSS 8.8
CVE-2024-39766 HIGH
Intel(R) Neural Compressor <v3.0 - Privilege Escalation
CVSS 7.0
CVE-2024-46366 HIGH
Webkul Krayin CRM 1.3.0 - Client-side Template Injection via Lead Creation
CVSS 8.8
CVE-2024-45053 CRITICAL
Fides 2.19.0-2.44.0 - Authenticated Remote Code Execution via Email Template Injection
CVSS 9.1
CVE-2024-6386 CRITICAL
WPML < 4.6.13 - Authenticated Remote Code Execution via Twig Server-Side Template Injection
CVSS 9.9
CVE-2024-42356 HIGH
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3
CVE-2024-42355 HIGH
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3
CVE-2024-41950 HIGH
Haystack < 2.3.1 - Remote Code Execution via Jinja2 Template Injection
CVSS 7.5
CVE-2024-38363 HIGH
Airbyte < 0.62.2 - Authenticated Remote Code Execution via Server-Side Template Injection
CVSS 8.5
CVE-2024-37621 HIGH
StrongShop 1.0 - Server-Side Template Injection in /shippingOptionConfig/index.blade.php
CVSS 7.2
CVE-2024-37301 HIGH
document-merge-service <= 6.5.1 - Remote Code Execution via Server-Side Template Injection
CVSS 7.2
CVE-2024-23692 CRITICAL KEV
Rejetto HTTP File Server - Template injection
CVSS 9.8
CVE-2024-34710 HIGH
Wiki.js <= 2.5.302 - Stored Cross-Site Scripting via Invalid HTML Tag Injection
CVSS 7.1
CVE-2024-35191 MEDIUM
Formie < 2.0.44 and 2.1.0-2.1.5 - Authenticated Server-Side Template Injection via Submission Title or Success Message
CVSS 4.4
CVE-2024-32406 HIGH
inducer relate < 2024.1 - Server-Side Template Injection via Batch-Issue Exam Tickets Function
CVSS 7.5
CVE-2024-32651 CRITICAL
changedetection.io <=0.45.20 - Remote Command Execution via Jinja2 SSTI
CVSS 10.0
CVE-2024-25624 MEDIUM
IRIS <2.4.6 - Authenticated Remote Code Execution via Report Template SSTI
CVSS 6.8
CVE-2024-4040 CRITICAL KEV
CrushFTP < 10.7.1 - Unauthenticated Server-Side Template Injection
CVSS 9.8
CVE-2024-24724 CRITICAL
Gibbon < 26.0.00 - Server-Side Template Injection via Messenger Settings
CVSS 9.8
CVE-2024-28116 HIGH
Grav < 1.7.45 - Authenticated Server-Side Template Injection
CVSS 8.8
CVE-2024-27623 MEDIUM
CMS Made Simple 2.2.19 - Server-Side Template Injection in Design Manager Breadcrumbs
CVSS 5.9
CVE-2023-6743 HIGH
Unlimited Elements For Elementor < 1.5.89 - Authenticated Remote Code Execution via Template Import
CVSS 8.8
CVE-2023-47542 MEDIUM
FortiManager <7.4.1, <7.2.4, <7.0.10 - Code Injection
CVSS 6.7
CVE-2023-5764 HIGH
Ansible < 2.14.12 and 2.16.0-2.16.1 - Template Injection via Unsafe Data Handling
CVSS 7.1
CVE-2023-6709 HIGH
mlflow/mlflow <2.9.2 - Info Disclosure
CVSS 8.8
Details
Vulnerabilities 193