Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 ERPNext versions up to v15.103.1 are affected by a Server-Side Template Injection (SSTI) vulnerability. This flaw allows an attacker with permissions to create or edit email templates to inject malicious template expressions that execute on the server during template rendering. The vulnerability has a critical severity rating with a CVSS score of 9.8, indicating high impact on confidentiality, integrity, and availability. No official patch or remediation guidance is currently provided by the vendor. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 05/05/2026, 00:00:00 UTC Added: 05/05/2026, 16:51:26 UTC |
0 An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using frappe.render_template() with a context derived from the address_dict parameter, which can be either a dictionary or a string referencing an Address document. Although ERPNext uses a custom Jinja2 SandboxedEnvironment, dangerous functions like frappe.db.sql remain accessible via get_safe_globals(). An authenticated attacker with permission to create or modify an Address Template can inject arbitrary Jinja expressions into the template field. By creating an Address document with a matching country, and then calling the get_address_display API with address_dict="address_name", the system will render the malicious template using attacker-controlled data. This leads to server-side code execution or database information disclosure. Join the discussion | CVE Database V5 | 12/15/2025, 00:00:00 UTC Added: 12/15/2025, 17:30:39 UTC |
Showing 1 to 2 of 2 results