<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Server-side Template Injection (SSTI) (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ssti.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ssti-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Server-side Template Injection (SSTI) (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:34 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-34906 – Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34906</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34906</strong></p>
  <p>Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoint redirectToUrl and parameter redirectUrlParameter, insufficient input validation permits injection of arbitrary template expressions that are executed on the server. Successful exploitation can allow an attacker to run remote commands, including est…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45312 – RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45312</guid>
    <pubDate>Fri, 29 May 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45312</strong></p>
  <p>RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server. Any normal user can register, create a Canvas workflow with a DuckDuckGo + LLM component chain, and trigger the SSTI.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9558 – A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9558</guid>
    <pubDate>Fri, 29 May 2026 11:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9558</strong></p>
  <p>A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44209 – Banks generates meaningful LLM prompts using a template language that makes sens...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44209</guid>
    <pubDate>Tue, 26 May 2026 21:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44209</strong></p>
  <p>Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to Prompt() are vulnerable to Server-Side Template Injection (SSTI), which can lead to Remote Code Execution (RCE) on the host system. This vulnerability is…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45714 – CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45714</guid>
    <pubDate>Wed, 13 May 2026 21:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45714</strong></p>
  <p>CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms). The application unsafely evaluates user-supplied input using the Smarty template engine without enabling Smarty Security Policies. This allows any authenticated u…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44377 – CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44377</guid>
    <pubDate>Wed, 13 May 2026 21:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44377</strong></p>
  <p>CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates and Documents). The application unsafely evaluates user-supplied input directly through the Smarty template engine. By leveraging this, an authenticated attacker with administrative privileges can bypass…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41901 – Thymeleaf is a server-side Java template engine for web and standalone environme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41901</guid>
    <pubDate>Tue, 12 May 2026 23:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41901</strong></p>
  <p>Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific sandboxed (restricted) contexts, it fails to properly neutralize specific constr…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-917</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44129 – SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side templ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44129</guid>
    <pubDate>Fri, 08 May 2026 14:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44129</strong></p>
  <p>SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new GINA UI because an endpoint accepts attacker-controlled template, allowing remote attackers to execute arbitrary template expressions and potentially achieve remote code execution depending on the enabled template plugins.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46507 – A SSTI (server side template injection) vulnerability in the custom template exp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46507</guid>
    <pubDate>Fri, 08 May 2026 06:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46507</strong></p>
  <p>A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33587 – Lack of user input sanitisation in Open Notebook v1.8.3 allows the application u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33587</guid>
    <pubDate>Thu, 07 May 2026 11:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33587</strong></p>
  <p>Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-38431 – ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38431</guid>
    <pubDate>Tue, 05 May 2026 17:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-38431</strong></p>
  <p>ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40478 – Thymeleaf is a server-side Java template engine for web and standalone environme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40478</guid>
    <pubDate>Fri, 17 Apr 2026 22:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40478</strong></p>
  <p>Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific syntax patterns that allow for the execution of unauthorized expressions. If an ap…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-917</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40477 – Thymeleaf is a server-side Java template engine for web and standalone environme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40477</guid>
    <pubDate>Fri, 17 Apr 2026 22:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40477</strong></p>
  <p>Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of accessible objects, allowing specific potentially sensitive objects to be reached fr…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-917</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34724 – Zammad is a web based open source helpdesk/customer support system. Prior to 7.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34724</guid>
    <pubDate>Wed, 08 Apr 2026 19:25:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34724</strong></p>
  <p>Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability  which leads to RCE via AI Agent exists. Impact is limited to environments where an attacker can control or influence type_enrichment_data (typically high-privilege administrative configuration). This vulnerability is fixed in 7.0.1.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28797 – RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28797</guid>
    <pubDate>Fri, 03 Apr 2026 22:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28797</strong></p>
  <p>RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing (StringTransform) and Message components. These components use Python's jinja2.Template (unsandboxed) to render user-supplied templates, allowing any authenticated user to execute arbitrary ope…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4257 – The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4257</guid>
    <pubDate>Mon, 30 Mar 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4257</strong></p>
  <p>The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig `Twig_Loader_String` template engine without sandboxing, combined with the `cfsPreFill` prefill functionality that allows unauthenticated users to inject arbitrary Twi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33154 – dynaconf is a configuration management tool for Python. Prior to version 3.2.13,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33154</guid>
    <pubDate>Fri, 20 Mar 2026 21:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33154</strong></p>
  <p>dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28697 – Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-bet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28697</guid>
    <pubDate>Wed, 04 Mar 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28697</strong></p>
  <p>Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). By calling the craft.app.fs.write() method, an attacker can write a malicious PHP script to a web-accessible directory and subseque…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28695 – Craft is a content management system (CMS). There is an authenticated admin RCE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28695</guid>
    <pubDate>Wed, 04 Mar 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28695</strong></p>
  <p>Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain. The create() Twig function exposes Craft::createObject(), which allows instantiation of arbitrary PHP classes with constructor arguments. Combined with the bundled symfony/process depen…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27961 – Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27961</guid>
    <pubDate>Thu, 26 Feb 2026 02:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27961</strong></p>
  <p>Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vulnerable code lives in the SDK package, it is executed server-side within the API process when running evaluators. This does not affect standalone SDK usage — it only impacts self-hosted or managed Ag…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27641 – Flask-Reuploaded provides file uploads for Flask. A critical path traversal and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27641</guid>
    <pubDate>Wed, 25 Feb 2026 04:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27641</strong></p>
  <p>Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI). Flask-Reuploaded has been patched in version 1.5.0. Some workarounds are available. Do not pass user input to the `name` parameter,…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-70830 – A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70830</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70830</guid>
    <pubDate>Tue, 17 Feb 2026 16:20:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-70830</strong></p>
  <p>A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70830">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25731 – calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25731</guid>
    <pubDate>Fri, 06 Feb 2026 21:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25731</strong></p>
  <p>calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or --template-html-index command-line options. This vulnerability is fixed in 9.2.0.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69516 – A Server-Side Template Injection (SSTI) vulnerability in the /reporting/template...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69516</guid>
    <pubDate>Thu, 29 Jan 2026 20:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69516</strong></p>
  <p>A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equal to or earlier than v1.3.1, allows low-privileged users with Report Viewer or Report Manager permissions to achieve remote command execution on the server. This occurs due to improper sanitization of the template_md parameter, enabling direct injec…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-64087 – A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker componen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64087</guid>
    <pubDate>Tue, 20 Jan 2026 16:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-64087</strong></p>
  <p>A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22244 – OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22244</guid>
    <pubDate>Thu, 08 Jan 2026 16:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22244</strong></p>
  <p>OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68454 – Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68454</guid>
    <pubDate>Mon, 05 Jan 2026 22:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68454</strong></p>
  <p>Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administrator access to the Craft Control Panel, and allowAdminChanges must be enabled, which is against Craft CMS' recommendations for any non-dev environment. Alterna…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-21450 – Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21450</guid>
    <pubDate>Fri, 02 Jan 2026 21:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-21450</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21449 – Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21449</guid>
    <pubDate>Fri, 02 Jan 2026 21:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21449</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege user. Version 2.3.10 fixes the issue.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-21448 – Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21448</guid>
    <pubDate>Fri, 02 Jan 2026 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-21448</strong></p>
  <p>Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The issue can lead to remote code execution. Version 2.3.10 contains a patch.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67843 – A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67843</guid>
    <pubDate>Fri, 19 Dec 2025 02:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67843</strong></p>
  <p>A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to execute arbitrary code via inline JSX expressions in an MDX file.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23851 – Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template inject...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23851</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23851</guid>
    <pubDate>Wed, 17 Dec 2025 15:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23851</strong></p>
  <p>Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23851">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14700 – An input neutralization vulnerability in the Webhook Template component of Craft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14700</guid>
    <pubDate>Wed, 17 Dec 2025 01:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14700</strong></p>
  <p>An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66438 – A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66438</guid>
    <pubDate>Mon, 15 Dec 2025 18:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66438</strong></p>
  <p>A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, the API frappe.www.printview.get_html_and_style() triggers the rendering of the html field inside a Print Format document using frappe.render_template(template, doc) via the get_rendered_template() call chain. Although ERPNext wraps Jinja2 in a Sandbox…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66437 – An SSTI (Server-Side Template Injection) vulnerability exists in the get_address...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66437</guid>
    <pubDate>Mon, 15 Dec 2025 18:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66437</strong></p>
  <p>An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using frappe.render_template() with a context derived from the address_dict parameter, which can be either a dictionary or a string referencing an Address document. Although ERPNext uses a custom Jinja2 SandboxedEnvironment, dan…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66434 – An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66434</guid>
    <pubDate>Mon, 15 Dec 2025 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66434</strong></p>
  <p>An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (body_text) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a custom SandboxedEnvironment, several dangerous globals such as frappe.db.sql are still available in the…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-58303 – FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-58303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-58303</guid>
    <pubDate>Thu, 11 Dec 2025 22:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-58303</strong></p>
  <p>FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution during email generation.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-58303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-58293 – Akaunting 3.1.8 contains a server-side template injection vulnerability that all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-58293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-58293</guid>
    <pubDate>Thu, 11 Dec 2025 22:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-58293</strong></p>
  <p>Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Attackers can inject template payloads in items, taxes, transactions, and vendor name fields to perform arithmetic operations and string manipulations.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-58293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66299 – Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66299</guid>
    <pubDate>Mon, 01 Dec 2025 22:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66299</strong></p>
  <p>Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypassing the existing security sandbox. Since the security sandbox does not fully protect the Twig object, it is possible to interact with it (e.g., call methods, rea…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66294 – Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Templat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66294</guid>
    <pubDate>Mon, 01 Dec 2025 21:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66294</strong></p>
  <p>Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, under certain conditions, may also be exploited by unauthenticated attackers. This vulnerability stems from weak regex validation in the cleanDangerousTwig method…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-60355 – zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60355</guid>
    <pubDate>Tue, 28 Oct 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-60355</strong></p>
  <p>zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10380 – The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10380</guid>
    <pubDate>Tue, 23 Sep 2025 04:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10380</strong></p>
  <p>The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template Injection in all versions up to, and including, 3.7.19. This is due to insufficient input sanitization and lack of access control when processing custom Twig templates in the Model panel. This makes it possible for authenticated attackers, with author-level access or higher, to e…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54815 – Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54815</guid>
    <pubDate>Fri, 19 Sep 2025 20:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54815</strong></p>
  <p>Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-9556 – Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9556</guid>
    <pubDate>Fri, 12 Sep 2025 14:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-9556</strong></p>
  <p>Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends syntax to read files, which leads to a server side template injection vulnerability within langchaingo, allowing an attacker to insert a statement into a prompt to read the "etc/passwd" file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-52122 – Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52122</guid>
    <pubDate>Wed, 27 Aug 2025 15:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-52122</strong></p>
  <p>Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57811 – Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57811</guid>
    <pubDate>Mon, 25 Aug 2025 18:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57811</strong></p>
  <p>Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to CVE-2024-52293. This vulnerability has been patched in versions 4.16.6 and 5.8.7.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-51991 – XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-51991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-51991</guid>
    <pubDate>Wed, 20 Aug 2025 15:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-51991</strong></p>
  <p>XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Preferences Presentation section. An authenticated administrator can inject crafted Apache Velocity template code, which is rendered on the server side without proper validation or sandboxing. This enables the execution of…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-51991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53909 – mailcow: dockerized is an open source groupware/email suite based on docker. A S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53909</guid>
    <pubDate>Thu, 17 Jul 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53909</strong></p>
  <p>mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notification template system used by mailcow for sending quota and quarantine alerts. The template rendering engine allows template expressions that may be abused to execute code in certain contexts. The issue requires admin-…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53833 – LaRecipe is an application that allows users to create documentation with Markdo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53833</guid>
    <pubDate>Mon, 14 Jul 2025 23:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53833</strong></p>
  <p>LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could potentially lead to Remote Code Execution (RCE) in vulnerable configurations. Attackers could execute arbitrary commands on the server, access sensitive environment variables, and/or escalate access de…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-5309 – The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5309</guid>
    <pubDate>Mon, 16 Jun 2025 17:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-5309</strong></p>
  <p>The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49619 – Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49619</guid>
    <pubDate>Sat, 07 Jun 2025 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49619</strong></p>
  <p>Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject crafted expressions that are evaluated on the server, leading to blind remote code execution (RCE).</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46731 – Craft is a content management system. Versions of Craft CMS on the 4.x branch pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46731</guid>
    <pubDate>Mon, 05 May 2025 20:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46731</strong></p>
  <p>Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1040 – AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Inje...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1040</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1040</strong></p>
  <p>AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from the improper handling of user-supplied format strings in the `AgentOutputBlock` implementation, where malicious input is passed to the Jinja2 templating engine without adequate security measures. Attackers can exploit this flaw…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-25362 – A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25362</guid>
    <pubDate>Wed, 05 Mar 2025 21:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-25362</strong></p>
  <p>A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-57177 – A host header injection vulnerability exists in the NPM package of perfood/couch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-57177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-57177</guid>
    <pubDate>Mon, 10 Feb 2025 20:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-57177</strong></p>
  <p>A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-23211 – Tandoor Recipes is an application for managing recipes, planning meals, and buil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23211</guid>
    <pubDate>Tue, 28 Jan 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-23211</strong></p>
  <p>Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerability is fixed in 1.5.24.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-50658 – Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50658</guid>
    <pubDate>Tue, 07 Jan 2025 18:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-50658</strong></p>
  <p>Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsBilling and firstname parameters in updateuserinfo.html file</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-12583 – The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12583</guid>
    <pubDate>Sat, 04 Jan 2025 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-12583</strong></p>
  <p>The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the ser…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36694 – OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36694</guid>
    <pubDate>Wed, 18 Dec 2024 20:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36694</strong></p>
  <p>OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55660 – SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYua...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55660</guid>
    <pubDate>Thu, 12 Dec 2024 02:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55660</strong></p>
  <p>SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables. Version 3.1.16 contains a patch for the issue.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52291 – Craft is a content management system (CMS). A vulnerability in CraftCMS allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52291</guid>
    <pubDate>Wed, 13 Nov 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52291</strong></p>
  <p>Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// scheme (e.g., file://file:////). This enables the attacker to specify sensitive folders as the file system, leading to potential file overwriting through malicious uploads, unauthorized access to sensitive files, and, under certain conditi…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52293 – Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52293</guid>
    <pubDate>Wed, 13 Nov 2024 16:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52293</strong></p>
  <p>Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code Execution on the server via twig SSTI. This is a sequel to CVE-2023-40035. This vulnerability is fixed in 4.12.2 and 5.4.3.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-45186 – FileSender before 2.49 allows server-side template injection (SSTI) for retrievi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45186</guid>
    <pubDate>Wed, 02 Oct 2024 05:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-45186</strong></p>
  <p>FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-45053 – Fides is an open-source privacy engineering platform. Starting in version 2.19.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45053</guid>
    <pubDate>Wed, 04 Sep 2024 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-45053</strong></p>
  <p>Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input sanitization or rendering environment restrictions, allowing for Server-Side Template Injection that grants Remote Code Execution to privileged users. A privileged user refers to an Admin UI user with the default `Owner` or `Co…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6386 – The WPML plugin for WordPress is vulnerable to Remote Code Execution in all vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6386</guid>
    <pubDate>Wed, 21 Aug 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6386</strong></p>
  <p>The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38363 – Airbyte is a data integration platform for ELT pipelines. Airbyte connection bui...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38363</guid>
    <pubDate>Tue, 09 Jul 2024 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38363</strong></p>
  <p>Airbyte is a data integration platform for ELT pipelines. Airbyte connection builder docker image is vulnerable to RCE via SSTI which allows an authenticated remote attacker to execute arbitrary code on the server as the web server user. The connection builder is used to create and test new connectors. Sensitive information, such as credentials, could be exposed if a user tested a new connector o…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37621 – StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37621</guid>
    <pubDate>Mon, 17 Jun 2024 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37621</strong></p>
  <p>StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shippingOptionConfig/index.blade.php.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-97</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37301 – Document Merge Service is a document template merge service providing an API to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37301</guid>
    <pubDate>Tue, 11 Jun 2024 19:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37301</strong></p>
  <p>Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of time of publication, no patched version exists, nor have any known workarounds bee…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34060 – IrisEVTXModule is an interface module for Evtx2Splunk and Iris in order to inges...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34060</guid>
    <pubDate>Thu, 23 May 2024 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34060</strong></p>
  <p>IrisEVTXModule is an interface module for Evtx2Splunk and Iris in order to ingest Microsoft EVTX log files. The `iris-evtx-module` is a pipeline plugin of `iris-web` that processes EVTX files through IRIS web application. During the upload of an EVTX through this pipeline, the filename is not safely handled and may cause an Arbitrary File Write. This can lead to a remote code execution (RCE) when…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-34359 – llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34359</guid>
    <pubDate>Tue, 14 May 2024 15:38:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-34359</strong></p>
  <p>llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loa…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-76</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32406 – Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32406</guid>
    <pubDate>Fri, 26 Apr 2024 04:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32406</strong></p>
  <p>Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-32651 – changedetection.io is an open source web page change detection, website watcher,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32651</guid>
    <pubDate>Fri, 26 Apr 2024 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-32651</strong></p>
  <p>changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-4040 – A server side template injection vulnerability in CrushFTP in all versions befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4040</guid>
    <pubDate>Mon, 22 Apr 2024 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-4040</strong></p>
  <p>A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22722 – Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22722</guid>
    <pubDate>Thu, 11 Apr 2024 20:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22722</strong></p>
  <p>Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-2952 – BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2952</guid>
    <pubDate>Wed, 10 Apr 2024 17:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-2952</strong></p>
  <p>BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerability arises from the `hf_chat_template` method processing the `chat_template` parameter from the `tokenizer_config.json` file through the Jinja template engine without proper sanitization. Attackers can exploit this by crafting malicious `tokenizer_config.json` files that execute a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-76</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-24724 – Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24724</guid>
    <pubDate>Wed, 03 Apr 2024 03:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-24724</strong></p>
  <p>Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-29686 – Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29686</guid>
    <pubDate>Fri, 29 Mar 2024 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-29686</strong></p>
  <p>Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin components. NOTE: the vendor disputes this because the payload could only be entered by a trusted user, such as the owner of the server that hosts Winter CMS, or a developer working for them.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-97</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28118 – Grav is an open-source, flat-file content management system. Prior to version 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28118</guid>
    <pubDate>Thu, 21 Mar 2024 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28118</strong></p>
  <p>Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Grav context, an attacker can redefine config variable. As a result, attacker can bypass a previous SSTI mitigation. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Tw…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28116 – Grav is an open-source, flat-file content management system. Grav CMS prior to v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28116</guid>
    <pubDate>Thu, 21 Mar 2024 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28116</strong></p>
  <p>Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any authenticated user (editor permissions are sufficient) to execute arbitrary code on the remote server bypassing the existing security sandbox. Version 1.7.45 contains a patch for this issue.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24230 – Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24230</guid>
    <pubDate>Mon, 18 Mar 2024 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24230</strong></p>
  <p>Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to execute arbitrary code via a URL that specifies java.lang.Runtime in conjunction with getRuntime().exec followed by an OS command.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28114 – Peering Manager is a BGP session management tool. There is a Server Side Templat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28114</guid>
    <pubDate>Tue, 12 Mar 2024 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28114</strong></p>
  <p>Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peering Manager <=1.8.2. As a result arbitrary commands can be executed on the operating system that is running Peering Manager. This issue has been addressed in version 1.8.3. Users are advised to upgrade. There are no known workarounds for this vulnera…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-27516 – Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27516</guid>
    <pubDate>Thu, 29 Feb 2024 01:44:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-27516</strong></p>
  <p>Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23761 – Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23761</guid>
    <pubDate>Mon, 12 Feb 2024 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23761</strong></p>
  <p>Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22533 – Before Beetl v3.15.12, the rendering template has a server-side template injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22533</guid>
    <pubDate>Fri, 02 Feb 2024 03:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22533</strong></p>
  <p>Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-41544 – SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41544</guid>
    <pubDate>Sat, 30 Dec 2023 04:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-41544</strong></p>
  <p>SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49964 – An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49964</guid>
    <pubDate>Mon, 11 Dec 2023 08:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49964</strong></p>
  <p>An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46245 – Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46245</guid>
    <pubDate>Tue, 31 Oct 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46245</strong></p>
  <p>Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig file, exploiting the software's PDF and HTML rendering functionalities. Version 2.1.0 enables security measures for custom…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46816 – An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46816</guid>
    <pubDate>Fri, 27 Oct 2023 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46816</strong></p>
  <p>An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing input validation. An attacker with regular user privileges can exploit this.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45303 – ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45303</guid>
    <pubDate>Fri, 06 Oct 2023 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45303</strong></p>
  <p>ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-29689 – PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29689</guid>
    <pubDate>Fri, 04 Aug 2023 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-29689</strong></p>
  <p>PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-36210 – MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36210</guid>
    <pubDate>Tue, 01 Aug 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-36210</strong></p>
  <p>MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37897 – Grav is a file-based Web-platform built in PHP. Grav is subject to a server side...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37897</guid>
    <pubDate>Tue, 18 Jul 2023 21:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37897</strong></p>
  <p>Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|filter` and `|reduce` twigs implemented in the commit `71bbed1` introduces bypass of the denylist due to incorrect return value from `isDangerousFunction()`, which allows to execute the payload prepending double backslash…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38286 – Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38286</guid>
    <pubDate>Fri, 14 Jul 2023 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38286</strong></p>
  <p>Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to environment variables via the UI.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-33570 – Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33570</guid>
    <pubDate>Wed, 28 Jun 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-33570</strong></p>
  <p>Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-31635 – Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31635</guid>
    <pubDate>Mon, 26 Jun 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-31635</strong></p>
  <p>Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-34448 – Grav is a flat-file content management system. Prior to version 1.7.42, the patc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34448</guid>
    <pubDate>Wed, 14 Jun 2023 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-34448</strong></p>
  <p>Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other built-in functions exposed by Twig's Core Extension that could be used to invoke arbitrary unsafe functions, thereby allowing for remote code execution. A patch in version 1.74.2…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-34251 – Grav is a flat-file content management system. Versions prior to 1.7.42 are vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34251</guid>
    <pubDate>Wed, 14 Jun 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-34251</strong></p>
  <p>Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page editing privileges. Version 1.7.42 contains a fix for this issue.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30179 – CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30179</guid>
    <pubDate>Tue, 13 Jun 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30179</strong></p>
  <p>CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this because only Administrators can add this Twig code, and (by design) Administrators are allowed to do that by default.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-30145 – Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30145</guid>
    <pubDate>Fri, 26 May 2023 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-30145</strong></p>
  <p>Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-29827 – ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29827</guid>
    <pubDate>Thu, 04 May 2023 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-29827</strong></p>
  <p>ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29827">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
