LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-str
Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary Angula
Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pul
A flaw has been found in datapizza-labs datapizza-ai 0.0.2. Affected is the function ChatPromptTemplate of the file data
A vulnerability has been found in OpenCart 4.0.2.3. Affected by this issue is the function Save of the file admin/contro
A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFree
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of th
A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/ja
An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an
In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a
Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic
In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered wit
Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests w
SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new G
Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Ex
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable t
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Temp
Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with th
A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway Se
CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template
Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.
Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine
The extension passes an editor-configurable email subject string directly into a Fluid template source without restricti
The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly i
Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the default-on "Safe impor
IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the at
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior
The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulne
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The
An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authentica
Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability
jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.
zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbi
Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).
mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vul
Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a ma
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to versi
Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with spec
Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts
Frequently Asked Questions
What is CWE-1336?
CWE-1336 (CWE-1336) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1336?
There are 236 CVE records associated with CWE-1336 in our database. Of these, 58 are critical severity, 94 are high severity, and 53 are medium severity.
How can I protect against CWE-1336 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1336 using AI-powered security agents.
Detect CWE-1336 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1336 vulnerabilities across your infrastructure.
Get Started