AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote C
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.
The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template I
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or e
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (S
An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext th
An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext throug
A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format renderin
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc
A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15
In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function fro
OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav config
A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially
A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical.
Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch pri
Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is
Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below con
Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions prior to 2.4.10 or
Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance co
An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended p
A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is
A vulnerability has been found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified
A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the functio
A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the l
Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticat
Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SS
A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Ha
An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext thro
An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext t
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects
A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f9
Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Speci
An issue was discovered in Logpoint AgentX before 1.5.0. A vulnerability caused by limited access controls allowed li-ad
Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ci
LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1
Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to exec
FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject
changedetection.io is an open source web page change detection, website watcher, restock monitor and notification servic
The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Tw
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms all
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vu
SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint
Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email
Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code
A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbi
Frequently Asked Questions
What is CWE-1336?
CWE-1336 (CWE-1336) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1336?
There are 236 CVE records associated with CWE-1336 in our database. Of these, 58 are critical severity, 94 are high severity, and 53 are medium severity.
How can I protect against CWE-1336 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1336 using AI-powered security agents.
Detect CWE-1336 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1336 vulnerabilities across your infrastructure.
Get Started