CWE-1336— Improper Neutralization of Special Elements Used in a Template Engine (SSTI)
The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.— MITRE CWE catalog
236 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1336page 5 of 5
- CVE-2026-55794HIGHCVSS 8.7EG 8.72026-07-02
Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header, potentially leading to authen…
- CVE-2026-57170HIGHCVSS 7.8EG 7.82026-08-25
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse…
- CVE-2026-5987MEDIUMCVSS 4.7EG 4.72026-04-09
A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFreemarkerView.doRender of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/common/base/AbstractFreemar…
- CVE-2026-59989CRITICALCVSS 9.2EG 9.22026-08-21
Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the join filter by inserting the raw separator and array token values into generated PHP with…
- CVE-2026-62681CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch, r…
- CVE-2026-62682CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in servers[0].url is emitted into request URL template literals generated when output.baseUrl.…
- CVE-2026-63728MEDIUMCVSS 6.3EG 6.32026-07-20
Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig …
- CVE-2026-65974CRITICALCVSS 9.9EG 9.92026-08-17
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forc…
- CVE-2026-66613CRITICALCVSS 9.8EG 9.82026-08-19
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
- CVE-2026-69118HIGHCVSS 8.8EG 8.82026-08-10
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade directi…
- CVE-2026-6984MEDIUMCVSS 4.7EG 4.72026-04-25
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard API. The manipulation results in improper neutralizat…
- CVE-2026-71239HIGHCVSS 8.1EG 8.12026-08-05
DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subj…
- CVE-2026-71286MEDIUMCVSS 6.1EG 6.12026-08-05
The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property directly into Ember/Glimmer's compileTemplate (from @ember/template-compilation) with no sanitization, allow-listing, …
- CVE-2026-71291HIGHCVSS 8.8EG 8.82026-08-05
Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTwigValue calls shouldBeRenderedAsTwig, which gates rendering…
- CVE-2026-71502MEDIUMCVSS 5.1EG 5.12026-08-06
CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conver…
- CVE-2026-71868CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum default is emitted into a module-level template literal emitted by zod sc…
- CVE-2026-71869CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an array item default is emitted into a module-level template literal emitted by …
- CVE-2026-71871CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header parameter default is emitted into a module-level template literal emitte…
- CVE-2026-71880HIGHCVSS 7.6EG 7.62026-08-18
Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via template injection
- CVE-2026-72716CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a query parameter default is emitted into a module-level template literal emitted…
- CVE-2026-72717CRITICALCVSS 9.3EG 9.32026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-level template literal emitted by zod s…
- CVE-2026-72827HIGHCVSS 8.8EG 8.82026-08-14
Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject Twig payloads using the …
- CVE-2026-72911CRITICALCVSS 9.9EG 9.92026-08-10
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py …
- CVE-2026-73299CRITICALCVSS 10.0EG 10.02026-08-12
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled…
- CVE-2026-73330MEDIUMCVSS 6.6EG 6.62026-08-12
CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are eval…
- CVE-2026-73505HIGHCVSS 7.8EG 7.82026-07-24
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function…
- CVE-2026-75574HIGHCVSS 8.8EG 8.82026-08-25
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can plac…
- CVE-2026-75829HIGHCVSS 8.1EG 8.12026-08-18
grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and conten…
- CVE-2026-75979MEDIUMCVSS 6.3EG 6.32026-08-19
A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sqlT…
- CVE-2026-77129HIGHCVSS 7.7EG 7.72026-08-25
The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this fi…
- CVE-2026-77136CRITICALCVSS 9.5EG 9.52026-08-25
The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can s…
- CVE-2026-78140MEDIUMCVSS 4.7EG 4.72026-08-23
A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component web-file-template Endpoint. Executi…
- CVE-2026-8740MEDIUMCVSS 6.3EG 6.32026-05-17
A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/TemplateResultDirective.java of the component templateResult A…
- CVE-2026-9177CRITICALCVSS 9.4EG 9.42026-07-29
A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an attacker with admin privileges to inject arbitrary…
- CVE-2026-9498MEDIUMCVSS 6.3EG 6.32026-05-25
A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument DefMsgTemplate.content leads to improper n…
- CVE-2026-9558CRITICALCVSS 9.9EG 9.92026-05-29
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload…
Map vulnerabilities like CWE-1336 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1336 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →