CVE-2026-9160
Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS probability
- 0.16%
- CWE
- CWE-1336
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- Arma Digital Media Inc. Website Template
Weakness type
Related vulnerabilities
- CVE-2025-34300 — Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
- CVE-2025-49136 — listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
- CVE-2026-75650 — Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
- CVE-2025-66294 — Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
- CVE-2026-33897 — Incus vulnerable to arbitrary file read and write through pongo templates
- CVE-2025-53833 — LaRecipe is vulnerable to Server-Side Template Injection attacks
- CVE-2025-47916 — Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
- CVE-2025-46661 — IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the at