CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
232 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-34300 — Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
- CVE-2024-4040 — Unauthenticated arbitrary file read and remote code execution in CrushFTP
- CVE-2024-23692 — Rejetto HTTP File Server 2.3m Unauthenticated RCE
- CVE-2025-49136 — listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
- CVE-2026-75650 — Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
- CVE-2025-66294 — Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
- CVE-2026-33897 — Incus vulnerable to arbitrary file read and write through pongo templates
- CVE-2025-53833 — LaRecipe is vulnerable to Server-Side Template Injection attacks
- CVE-2025-47916 — Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
- CVE-2025-46661 — IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the at
- CVE-2025-23211 — Tandoor Recipes - SSTI - Remote Code Execution
- CVE-2024-32651 — Server Side Template Injection in Jinja2 allows Remote Command Execution
- CVE-2026-1868 — Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway
- CVE-2025-32461 — wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The
- CVE-2025-14700 — Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
- CVE-2026-25526 — JinJava Bypass through ForTag leads to Arbitrary Java Execution
- CVE-2025-59340 — jinjava Sandbox Bypass via JavaType-Based Deserialization
- CVE-2026-28783 — Craft has a Twig Function Blocklist Bypass
- CVE-2026-28697 — Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates
- CVE-2024-52427 — WordPress Event Tickets with Ticket Scanner plugin <= 2.3.11 - Remote Code Execution (RCE) vulnerability
Recently published
- CVE-2026-87021 — Tanium addressed an unauthorized code execution vulnerability in Comply.
- CVE-2026-33387 — Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0
- CVE-2026-75650 — Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
- CVE-2026-52762 — YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
- CVE-2026-46636 — Twig: Sandbox method allowlist bypass via `Markup` subclass
- CVE-2026-85654 — Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
- CVE-2026-13297 — Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
- CVE-2026-75036 — Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing
- CVE-2026-82958 — In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a Cr
- CVE-2026-12894 — Io.quarkus:quarkus-qute: quarkus-qute:server-side template injection (ssti) vulnerability in reflectionvalueresolver of the quarkus qute template engine
- CVE-2026-82447 — Skyvern before 1.0.45 Sandbox Escape via TextPromptBlock
- CVE-2026-55559 — Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)
- CVE-2026-77939 — Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint
- CVE-2026-54718 — Silverstripe Advanced Workflow: Remote code execution via advanced workflow email template
- CVE-2026-47727 — Trilium: RCE via `shareTemplate` relation missing `isDangerous` flag — Safe import bypass leading to EJS SSTI (Incomplete Fix of CVE-2026-45668)
- CVE-2026-57170 — Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)
- CVE-2026-77129 — Server-Side Template Injection in extension "Event management and registration" (sf_event_mgt)
- CVE-2026-77136 — Server-Side Template Injection in extension "powermail" (powermail)
- CVE-2026-75574 — Grav before 4.2.2 Remote Code Execution via Email Twig
- CVE-2026-78140 — Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine