VYPR

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

BaseIncomplete

Description

The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (267)

page 7 of 14
  • CVE-2025-66299HigDec 1, 2025
    risk 0.50cvss 8.8epss 0.01

    Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypassing the existing security sandbox. Since…

  • CVE-2025-66297HigDec 1, 2025
    risk 0.50cvss 8.8epss 0.01

    Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the page frontmatter. By injecting malicious Twig expressions, the user can escalate their privileges to…

  • CVE-2025-49828HigJul 15, 2025
    risk 0.50cvss 8.8epss 0.02

    Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.4.1 are vulnerable to remote code execution An authenticated attacker…

  • CVE-2025-27516HigMar 5, 2025
    risk 0.50cvss 8.8epss 0.01

    Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker…

  • CVE-2024-25131HigDec 19, 2024
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object with a specially crafted file and set the most privileged service account to run the job. This can…

  • CVE-2024-48962HigNov 18, 2024
    risk 0.50cvss 8.8epss 0.01

    Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to…

  • CVE-2023-6743HigMay 29, 2024
    risk 0.50cvss 8.8epss 0.01

    The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.89 via the template import functionality. This makes it possible for authenticated attackers, with…

  • CVE-2023-6709HigDec 12, 2023
    risk 0.50cvss 8.8epss 0.01

    Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to 2.9.2.

  • CVE-2023-34253HigJun 14, 2023
    risk 0.50cvss 8.8epss 0.02

    Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily subverted in multiple ways -- (1) using…

  • CVE-2023-34252HigJun 14, 2023
    risk 0.50cvss 8.8epss 0.02

    Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby validation against a denylist of unsafe functions is only performed when the argument passed to filter is a string. However,…

  • CVE-2022-0896HigMar 9, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2022-0323HigJan 21, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.

  • CVE-2026-13297HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.

  • CVE-2026-47727HigAug 27, 2026
    risk 0.49cvss —epss 0.00

    Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the default-on "Safe import" filter fails to neutralize the shareTemplate relation because that relation is not marked as dangerous, allowing an attacker-supplied import archive to…

  • CVE-2026-71880HigAug 18, 2026
    risk 0.49cvss —epss 0.00

    Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via template injection

  • CVE-2024-32406HigApr 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function.

  • CVE-2026-32261HigMar 16, 2026
    risk 0.48cvss —epss 0.00

    Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests when certain events occur. From version 3.0.0 to before version 3.2.0, the Webhooks plugin renders user-supplied template content through Twig’s…

  • CVE-2024-38363HigJul 9, 2024
    risk 0.48cvss 8.5epss 0.01

    Airbyte is a data integration platform for ELT pipelines. Airbyte connection builder docker image is vulnerable to RCE via SSTI which allows an authenticated remote attacker to execute arbitrary code on the server as the web server user. The connection builder is used to create…

  • CVE-2026-87021HigSep 9, 2026
    risk 0.47cvss 7.2epss 0.00

    Tanium addressed an unauthorized code execution vulnerability in Comply.

  • CVE-2026-54666HigJul 29, 2026
    risk 0.47cvss 8.3epss 0.00

    swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and templates/modular/procedure-call.ejs…