Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization
Airbyte is a data integration platform for ELT pipelines. Airbyte connection builder docker image is vulnerable to RCE v
Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages wh
Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into a
Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects ca
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execut
Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vecto
Document Merge Service is a document template merge service providing an API to manage templates and merge them with giv
StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shipp
Wiki.js is al wiki app built on Node.js. Client side template injection was discovered, that could allow an attacker to
Improper neutralization of special elements used in SQL command in some Intel(R) Neural Compressor software before versi
Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations.
A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and be
PenDoc is a penetration testing reporting application. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an atta
Allegra getLinkText Server-Side Template Injection Remote Code Execution Vulnerability. This vulnerability allows remote
CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within t
Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include mali
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Imprope
Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopwar
Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filt
Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prev
Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side templ
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to 2.9.2.
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 throug
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2
Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Templ
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the u
OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a vulnerability th
A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unkn
Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior t
In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can ins
Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1.
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Template Injecti
Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers
Frequently Asked Questions
What is CWE-1336?
CWE-1336 (CWE-1336) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1336?
There are 236 CVE records associated with CWE-1336 in our database. Of these, 58 are critical severity, 94 are high severity, and 53 are medium severity.
How can I protect against CWE-1336 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1336 using AI-powered security agents.
Detect CWE-1336 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1336 vulnerabilities across your infrastructure.
Get Started