High severity8.2NVD Advisory· Published Jan 4, 2022· Updated Jun 17, 2026
CVE-2022-21648
CVE-2022-21648
Description
Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue is fixed in the versions 2.8.8, 2.9.6 and 2.10.8. Users unable to upgrade should not accept template input from untrusted sources.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
latte/lattePackagist | >= 2.10.0, < 2.10.8 | 2.10.8 |
latte/lattePackagist | >= 2.9.0, < 2.9.6 | 2.9.6 |
latte/lattePackagist | >= 2.8.0, < 2.8.8 | 2.8.8 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/nette/latte/commit/9e1b4f7d70f7a9c3fa6753ffa7d7e450a3d4abb0nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-36m2-8rhx-f36jghsaADVISORY
- github.com/nette/latte/security/advisories/GHSA-36m2-8rhx-f36jnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-21648ghsaADVISORY
News mentions
0No linked articles in our index yet.