CWE-97: Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
The product generates a web page, but does not neutralize or incorrectly neutralizes user-controllable input that could be interpreted as a server-side include (SSI) directive.
5 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-35996 — KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
- CVE-2025-21103 — Dell NetWorker Management Console, version(s) 19.11 through 19.11.0.3 & Versions prior to 19.10.0.7 contain(s) an improp
- CVE-2024-56363 — APTRS has SSTI vulnerability
- CVE-2025-36558 — KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
Recently published
- CVE-2025-36558 — KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
- CVE-2025-35996 — KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
- CVE-2025-21103 — Dell NetWorker Management Console, version(s) 19.11 through 19.11.0.3 & Versions prior to 19.10.0.7 contain(s) an improp
- CVE-2024-56363 — APTRS has SSTI vulnerability