Skip to main content

CWE archive

CWE-1336 CVEs

Programmatic archive

215 CVEs tagged with CWE-133656 Critical, 97 High, 46 Medium, 16 Low, 0 Unrated.

CVE-2026-71880

Published Aug 18, 2026

Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files…

CVSS 7.6 · High
evidence mentions
3

CVE-2026-75829

Published Aug 18, 2026

grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-65974

Published Aug 17, 2026

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe exec…

CVSS 9.9 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-44845

Published Aug 17, 2026

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and…

CVSS 6.7 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-19929

Published Aug 16, 2026

A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.…

CVSS 2.1 · Low
evidence mentions
10
Buzz score
32.0

CVE-2026-46439

Published Aug 14, 2026

compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in t…

CVSS 7.8 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-72827

Published Aug 14, 2026

Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-sy…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-13051

Published Aug 13, 2026

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that val…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
31.1

CVE-2022-4993

Published Aug 13, 2026

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text bui…

CVSS 9.1 · Critical
evidence mentions
6
Buzz score
39.5

CVE-2026-73505

Published Aug 13, 2026

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which i…

CVSS 7.8 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-73330

Published Aug 12, 2026

CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-73299

Published Aug 12, 2026

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with u…

CVSS 10.0 · Critical
evidence mentions
6
Buzz score
24.5

CVE-2026-72911

Published Aug 10, 2026

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/pro…

CVSS 9.9 · Critical
evidence mentions
7
Buzz score
25.8

CVE-2026-69118

Published Aug 10, 2026

Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attacker…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-71502

Published Aug 8, 2026

CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled d…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-5336

Published Aug 6, 2026

The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to it, a…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-15734

Published Aug 6, 2026

A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-71291

Published Aug 5, 2026

Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getT…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-71286

Published Aug 5, 2026

The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property directly into Ember/Glimmer's compileTemplate (from @ember…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-71239

Published Aug 5, 2026

DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: m…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-18632

Published Aug 3, 2026

A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transf…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-54666

Published Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys throug…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-54664

Published Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.sc…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-54662

Published Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into a…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1
Showing 1-25 of 215 CVEsPage 1 of 9