VYPR

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

BaseIncomplete

Description

The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (218)

page 11 of 11
  • CVE-2025-3841LowApr 21, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.py of the component Jinja2 Template Handler. The manipulation of the argument config['template']…

  • CVE-2026-44916LowMay 8, 2026
    risk 0.20cvss 3.0epss 0.00

    In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.

  • CVE-2026-52796LowJun 24, 2026
    risk 0.16cvss 3.5epss 0.00

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial of service. In internal/markup/markup.go, RenderIssueIndexPattern renders the issue index pattern to a link using…

  • CVE-2025-23376LowApr 28, 2025
    risk 0.15cvss 2.3epss 0.00

    Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to…

  • CVE-2022-0944HigMar 15, 2022
    risk 0.01cvss 7.2epss 0.09

    Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1.

  • CVE-2026-9177CriJul 29, 2026
    risk 0.00cvss epss 0.00

    A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an attacker with admin privileges to inject arbitrary Java code expressions, which are …

  • CVE-2026-54621HigJul 28, 2026
    risk 0.00cvss 7.8epss 0.00

    datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_code_generator/model/template/UnionTypeStatement.jinja2 and src/datamodel_code_generator/model/template/UnionTypeStatement.py312.jinja…

  • CVE-2026-47752CriJul 23, 2026
    risk 0.00cvss 9.9epss 0.00

    Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed…

  • CVE-2026-47690HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration of `GITHUB_TOKEN` with write permissions to the repository. The vulnerable…

  • CVE-2026-63728MedJul 21, 2026
    risk 0.00cvss 6.3epss 0.00

    Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig template functions. Attackers can craft…

  • CVE-2026-55242HigJul 15, 2026
    risk 0.00cvss 8.8epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data…

  • CVE-2026-55794HigJul 2, 2026
    risk 0.00cvss epss 0.00

    Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header, potentially leading to authenticated RCE. The issue happens when a…

  • CVE-2026-25731HigFeb 6, 2026
    risk 0.00cvss 7.8epss 0.00

    calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or…

  • CVE-2025-62369HigNov 4, 2025
    risk 0.00cvss 7.2epss 0.01

    Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating functionality, allowing authenticated users with "System -> Add/Edit…

  • CVE-2025-53909CriJul 17, 2025
    risk 0.00cvss 9.1epss 0.00

    mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notification template system used by mailcow for sending quota and quarantine alerts. The template…

  • CVE-2025-1040HigMar 20, 2025
    risk 0.00cvss 8.8epss 0.02

    AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from the improper handling of user-supplied format strings in the `AgentOutputBlock` implementation, where…

  • CVE-2025-23211CriJan 28, 2025
    risk 0.00cvss 9.9epss 0.04

    Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerability is fixed in 1.5.24.

  • CVE-2023-2259HigApr 24, 2023
    risk 0.00cvss 7.2epss 0.01

    Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.