VYPR

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

BaseIncomplete

Description

The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (218)

page 7 of 11
  • CVE-2023-27995HigApr 11, 2023
    risk 0.47cvss 7.2epss 0.01

    A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.

  • CVE-2021-39128HigSep 16, 2021
    risk 0.47cvss 7.2epss 0.02

    Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators access to execute arbitrary Java code via a server-side template injection vulnerability in the Email Template feature. The affected…

  • CVE-2018-20465HigDec 25, 2018
    risk 0.47cvss 7.2epss 0.02

    Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes…

  • CVE-2026-41713HigMay 12, 2026
    risk 0.46cvss 8.2epss 0.00

    A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns.

  • CVE-2026-34587HigApr 24, 2026
    risk 0.46cvss 8.1epss 0.00

    Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint…

  • CVE-2024-39766HigNov 13, 2024
    risk 0.46cvss 7.0epss 0.00

    Improper neutralization of special elements used in SQL command in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2026-39379higJul 1, 2026
    risk 0.45cvss epss

    ### Summary It is possible to craft a URL that causes GeoNetwork to reflect attacker-controlled content into an error page in a way that gets evaluated as a client-side template expression. Combined with known AngularJS sandbox-escape techniques, this can be used to execute…

  • CVE-2025-26789MedFeb 14, 2025
    risk 0.45cvss epss 0.00

    An issue was discovered in Logpoint AgentX before 1.5.0. A vulnerability caused by limited access controls allowed li-admin users to access sensitive information about AgentX Manager in a Logpoint deployment.

  • CVE-2026-46439HigAug 14, 2026
    risk 0.44cvss 7.8epss 0.00

    compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an…

  • CVE-2026-73505HigAug 13, 2026
    risk 0.44cvss 7.8epss

    Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an…

  • CVE-2026-5336MedAug 6, 2026
    risk 0.44cvss 6.8epss 0.00

    The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to it, allowing users with a role as low as Contributor to disclose sensitive information, such as the…

  • CVE-2026-54654HigJul 28, 2026
    risk 0.44cvss 7.8epss 0.00

    datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-template-data comment field is rendered into Python comments in src/datamodel_code_generator/model/template/TypeAliasAnnotation.jinja2,…

  • CVE-2024-56326HigDec 23, 2024
    risk 0.44cvss 7.8epss 0.01

    Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker needs…

  • CVE-2024-25624MedApr 25, 2024
    risk 0.44cvss 6.8epss 0.01

    Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. Due to an improper setup of Jinja2 environment, reports generation in `iris-web` is prone to a Server Side Template Injection (SSTI). Successful exploitation…

  • CVE-2023-47542MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.00

    A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and 7.0.10 and below allows attacker to execute unauthorized code or commands via specially crafted templates.

  • CVE-2026-44209HigMay 26, 2026
    risk 0.42cvss 7.5epss 0.01

    Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to Prompt() are vulnerable to…

  • CVE-2026-29207MedMay 19, 2026
    risk 0.42cvss 6.5epss 0.01

    Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Please note that in the updated version, "Data…

  • CVE-2026-34202HigMar 31, 2026
    risk 0.42cvss 7.5epss 0.01

    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a…

  • CVE-2026-33154HigMar 20, 2026
    risk 0.42cvss 7.5epss 0.01

    dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template…

  • CVE-2025-66298HigDec 1, 2025
    risk 0.42cvss 7.5epss 0.00

    Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload to exploit a Server-Side Template (SST) vulnerability. Sensitive…