CVE-2025-12107
Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates. Successful exploitation of this vulnerability could allow a malicious actor with admin privilege to inject and execute arbitrary template code on the server, potentially leading to remote code execution, data manipulation, or unauthorized access to sensitive information.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.62%
- CWE
- CWE-1336, CWE-77, CWE-94
- Published
- 2026-02-19
- Last modified
- 2026-09-03
Affected products
- WSO2 WSO2 Identity Server
- WSO2 Identity Server
- WSO2 Identity Server
- WSO2 Identity Server
- WSO2 Identity Server
Weakness type
Related vulnerabilities
- CVE-2025-34300 — Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
- CVE-2025-49136 — listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
- CVE-2026-75650 — Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
- CVE-2025-66294 — Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
- CVE-2026-33897 — Incus vulnerable to arbitrary file read and write through pongo templates
- CVE-2025-53833 — LaRecipe is vulnerable to Server-Side Template Injection attacks
- CVE-2025-47916 — Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
- CVE-2025-46661 — IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the at