Total
131 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-28783 | 1 Craftcms | 1 Craft Cms | 2026-03-05 | N/A | 9.1 CRITICAL |
|
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be able to successfully execute this attack, you need to either have allowAdminChanges enabled on production, or a compromised admin account, or an account with access to the System Messages utility. Several PHP functions are not included in the blocklist, which coul ...
Show More |
|||||
| CVE-2026-28695 | 1 Craftcms | 1 Craft Cms | 2026-03-05 | N/A | 7.2 HIGH |
|
Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain. The create() Twig function exposes Craft::createObject(), which allows instantiation of arbitrary PHP classes with constructor arguments. Combined with the bundled symfony/process dependency, this enables RCE. This bypasses the fix implemented for CVE-2025-57811 (patched in 5.8.7). Thi ...
Show More |
|||||
| CVE-2026-28784 | 1 Craftcms | 1 Craft Cms | 2026-03-05 | N/A | 7.2 HIGH |
|
Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload using the Twig map filter in text fields that accept Twig input under Settings in the Craft control panel or using the System Messages utility, which could lead to a RCE. For this to work, you must have administrator access to the Craft Control Panel, and allowAdminChanges must be enabled for this to work, which is against our recommendations for any non-dev environment. Alternati ...
Show More |
|||||
| CVE-2026-28697 | 1 Craftcms | 1 Craft Cms | 2026-03-05 | N/A | 9.1 CRITICAL |
|
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). By calling the craft.app.fs.write() method, an attacker can write a malicious PHP script to a web-accessible directory and subsequently access it via the browser to execute arbitrary system commands. This vulnerability is fixed in 4 ...
Show More |
|||||
| CVE-2025-60355 | 1 Zhyd | 1 Oneblog | 2026-03-04 | N/A | 9.8 CRITICAL |
|
zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
|
|||||
| CVE-2026-27961 | 1 Agentatech | 1 Agenta | 2026-03-02 | N/A | 8.8 HIGH |
|
Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vulnerable code lives in the SDK package, it is executed server-side within the API process when running evaluators. This does not affect standalone SDK usage — it only impacts self-hosted or managed Agenta platform deployments. Version 0.86.8 contains a fix for the issue.
|
|||||
| CVE-2026-26938 | 1 Elastic | 1 Kibana | 2026-03-02 | N/A | 8.6 HIGH |
|
Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.
|
|||||
| CVE-2026-27464 | 1 Metabase | 1 Metabase | 2026-03-02 | N/A | 7.7 HIGH |
|
Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to retrieve sensitive information from a Metabase instance, including database access credentials. During testing, it was confirmed that a low-privileged user can extract sensitive information including database credentials, into the email body via template evaluation. This issue has been fixed in versions 0.57.13 and 0.58.7. To workaround this issue, ...
Show More |
|||||
| CVE-2026-27629 | 1 Inventree Project | 1 Inventree | 2026-02-27 | N/A | 5.9 MEDIUM |
|
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure information to the client. When generating custom batch codes, the InvenTree server makes use of a customizable jinja2 template, which can be modified by a staff user to exfiltrate sensitive information or perform code execution on the server. This issue requires access by a user with granted staff permissions, followed by a request to generate a custom ...
Show More |
|||||
| CVE-2026-27641 | 1 Jugmac00 | 1 Flask-reuploaded | 2026-02-27 | N/A | 9.8 CRITICAL |
|
Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI). Flask-Reuploaded has been patched in version 1.5.0. Some workarounds are available. Do not pass user input to the `name` parameter, use auto-generated filenames only, and implement strict input validation if `name` must be used.
|
|||||
| CVE-2024-4040 | 1 Crushftp | 1 Crushftp | 2026-02-26 | N/A | 9.8 CRITICAL |
|
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
|
|||||
| CVE-2026-2969 | 1 Datapizza | 1 Datapizza Ai | 2026-02-24 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A flaw has been found in datapizza-labs datapizza-ai 0.0.2. Affected is the function ChatPromptTemplate of the file datapizza-ai-core/datapizza/modules/prompt/prompt.py of the component Jinja2 Template Handler. This manipulation of the argument Prompt causes improper neutralization of special elements used in a template engine. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in ...
Show More |
|||||
| CVE-2026-25526 | 1 Hubspot | 1 Jinjava | 2026-02-20 | N/A | 9.8 CRITICAL |
|
JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox restrictions. This issue has been patched in versions 2.7.6 and 2.8.3.
|
|||||
| CVE-2025-12107 | 1 Wso2 | 1 Identity Server | 2026-02-19 | N/A | 10.0 CRITICAL |
|
Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates.
Successful exploitation of this vulnerability could allow a malicious actor with admin privilege to inject and execute arbitrary template code on the server, potentially leading to remote code execution, data manipulation, or unauthorized access to sensitive information.
|
|||||
| CVE-2026-23626 | 1 Kimai | 1 Kimai | 2026-02-18 | N/A | 6.8 MEDIUM |
|
Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a Twig sandbox with an overly permissive security policy (`DefaultPolicy`) that allows arbitrary method calls on objects available in the template context. An authenticated user with export permissions can deploy a malicious Twig template that extracts sensitive information including environment variables, all user password hashes, serialized session tokens, and CSRF tokens. Vers ...
Show More |
|||||
| CVE-2026-25731 | 1 Calibre-ebook | 1 Calibre | 2026-02-17 | N/A | 7.8 HIGH |
|
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or --template-html-index command-line options. This vulnerability is fixed in 9.2.0.
|
|||||
| CVE-2025-69516 | 1 Amidaware | 1 Tactical Rmm | 2026-02-13 | N/A | 8.8 HIGH |
|
A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equal to or earlier than v1.3.1, allows low-privileged users with Report Viewer or Report Manager permissions to achieve remote command execution on the server. This occurs due to improper sanitization of the template_md parameter, enabling direct injection of Jinja2 templates. This occurs due to misuse of the generate_html() function, the user-control ...
Show More |
|||||
| CVE-2026-1868 | 2026-02-09 | N/A | 9.9 CRITICAL | ||
|
GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions. This vulnerability could be used to cause Denial of Service or gain code execution on the Gateway. This has been fixed in versions 18.6.2, 18.7.1, and 18.8.1 of the Gi ...
Show More |
|||||
| CVE-2024-37301 | 2026-02-04 | N/A | 7.2 HIGH | ||
|
Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds been disclosed.
|
|||||
| CVE-2025-64087 | 1 Opensagres | 1 Xdocreport | 2026-02-03 | N/A | 9.8 CRITICAL |
|
A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.
|
|||||
| CVE-2025-46699 | 1 Dell | 1 Data Protection Advisor | 2026-01-28 | N/A | 4.3 MEDIUM |
|
Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a Template Engine vulnerability in the Server. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
|
|||||
| CVE-2026-22244 | 1 Open-metadata | 1 Openmetadata | 2026-01-15 | N/A | 7.2 HIGH |
|
OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch.
|
|||||
| CVE-2025-68454 | 1 Craftcms | 1 Craft Cms | 2026-01-12 | N/A | 8.8 HIGH |
|
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administrator access to the Craft Control Panel, and allowAdminChanges must be enabled, which is against Craft CMS' recommendations for any non-dev environment. Alternatively, a non-administrator account with allowAdminChanges disabled can be used, provided access to t ...
Show More |
|||||
| CVE-2026-21448 | 1 Webkul | 1 Bagisto | 2026-01-08 | N/A | 9.8 CRITICAL |
|
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The issue can lead to remote code execution. Version 2.3.10 contains a patch.
|
|||||
| CVE-2026-21449 | 1 Webkul | 1 Bagisto | 2026-01-08 | N/A | 8.8 HIGH |
|
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege user. Version 2.3.10 fixes the issue.
|
|||||
| CVE-2026-21450 | 1 Webkul | 1 Bagisto | 2026-01-08 | N/A | 9.8 CRITICAL |
|
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.
|
|||||
| CVE-2025-66438 | 1 Frappe | 1 Erpnext | 2026-01-05 | N/A | 8.8 HIGH |
|
A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, the API frappe.www.printview.get_html_and_style() triggers the rendering of the html field inside a Print Format document using frappe.render_template(template, doc) via the get_rendered_template() call chain. Although ERPNext wraps Jinja2 in a SandboxedEnvironment, it exposes sensitive functions such as frappe.db.sql through get_safe_globals(). An au ...
Show More |
|||||
| CVE-2025-66437 | 1 Frappe | 1 Erpnext | 2026-01-05 | N/A | 8.8 HIGH |
|
An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using frappe.render_template() with a context derived from the address_dict parameter, which can be either a dictionary or a string referencing an Address document. Although ERPNext uses a custom Jinja2 SandboxedEnvironment, dangerous functions like frappe.db.sql remain accessible via get_safe_globals(). An authenticated attack ...
Show More |
|||||
| CVE-2022-23851 | 1 Netaxis | 1 Api Orchestrator | 2026-01-05 | N/A | 9.8 CRITICAL |
|
Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).
|
|||||
| CVE-2025-67843 | 1 Mintlify | 1 Mintlify | 2026-01-02 | N/A | 8.3 HIGH |
|
A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to execute arbitrary code via inline JSX expressions in an MDX file.
|
|||||
| CVE-2025-68929 | 1 Frappe | 1 Frappe | 2025-12-31 | N/A | 9.0 CRITICAL |
|
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.
|
|||||
| CVE-2025-14731 | 1 Ctcms Project | 1 Ctcms | 2025-12-24 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component Frontend/Template Management Module. This manipulation causes improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
|
|||||
| CVE-2025-14700 | 1 Craftycontrol | 1 Crafty Controller | 2025-12-23 | N/A | 9.9 CRITICAL |
|
An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.
|
|||||
| CVE-2025-66434 | 1 Frappe | 1 Erpnext | 2025-12-23 | N/A | 8.8 HIGH |
|
An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (body_text) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals such as frappe.db.sql are still available in the execution context via get_safe_globals(). An authenticated attacker with access to configure Dunning ...
Show More |
|||||
| CVE-2025-66435 | 1 Frappe | 1 Erpnext | 2025-12-23 | N/A | 4.3 MEDIUM |
|
An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (contract_terms) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals such as frappe.db.sql are still available in the execution context via get_safe_globals(). An authenticated attacker with access to create or modif ...
Show More |
|||||
| CVE-2025-66436 | 1 Frappe | 1 Erpnext | 2025-12-23 | N/A | 4.3 MEDIUM |
|
An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (terms) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals such as frappe.db.sql are still available in the execution context via get_safe_globals(). An authenticated attacker with access to create or modify a Te ...
Show More |
|||||
| CVE-2025-65602 | 1 Chancms | 1 Chancms | 2025-12-18 | N/A | 9.8 CRITICAL |
|
A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.
|
|||||
| CVE-2024-57177 | 2025-12-17 | N/A | 7.3 HIGH | ||
|
A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information
|
|||||
| CVE-2024-32406 | 1 Inducer | 1 Relate | 2025-12-17 | N/A | 7.5 HIGH |
|
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function.
|
|||||
| CVE-2024-27623 | 1 Cmsmadesimple | 1 Cms Made Simple | 2025-12-17 | N/A | 5.9 MEDIUM |
|
CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.
|
|||||