Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which cou
Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject a
swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templat
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-
swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch
swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch
A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an uninte
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control w
DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template const
grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers wit
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templit
Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rende
datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union descriptio
datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-tem
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle
compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Serv
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions
Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, aut
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side T
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerabi
Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Env
MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to
OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server
Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Temp
Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload usi
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vul
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attacker
Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an
Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a
JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template
The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template ren
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an a
CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to ex
Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9p
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attack
A flaw has been found in 1024-lab/lab1024 SmartAdmin up to 3.29. Affected by this issue is the function freemarkerResolv
A vulnerability has been found in AntaresMugisho PyBlade 0.1.8-alpha/0.1.9-alpha. The affected element is the function _
A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccm
A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass
Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence r
A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of
A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails
A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewS
The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be h
The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assi
InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PA
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
Frequently Asked Questions
What is CWE-1336?
CWE-1336 (CWE-1336) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1336?
There are 133 CVE records associated with CWE-1336 in our database. Of these, 34 are critical severity, 45 are high severity, and 32 are medium severity.
How can I protect against CWE-1336 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1336 using AI-powered security agents.
Detect CWE-1336 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1336 vulnerabilities across your infrastructure.
Get Started