Threats Tagged 'cwe-1336'
View all threats tagged with 'cwe-1336'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1336'
Click on any threat for detailed analysis and mitigation recommendations
0 Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be evaluated by the isolated Twig renderer when rendered into HTML attributes. An unauthenticated attacker can place Twig expressions in submitted field values, including value attributes, and receive evaluated PHP, operating-system, or Craft filesystem-path constants in the form response. The isolated context was not shown to expose Craft globals, environment variables, credentials, arbitrary files, or code execution, so the confirmed impact is limited server and environment information disclosure and possible rendering errors. This issue is fixed in version 5.10.14. Join the discussion | CVE Database V5 | 09/23/2026, 14:30:22 UTC Added: 09/23/2026, 14:48:31 UTC |
0 ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution. Join the discussion | CVE Database V5 | 09/23/2026, 11:20:09 UTC Added: 09/23/2026, 11:33:33 UTC |
Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | GCVE Database | 09/11/2026, 17:08:57 UTC Added: 09/11/2026, 22:20:42 UTC |
Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 09/11/2026, 17:08:57 UTC Added: 09/11/2026, 17:32:57 UTC |
0 CVE-2026-19584 is a vulnerability in Rapid7 Velociraptor affecting versions from 0 up to but not including 0.77.2. It involves improper neutralization of special elements in a template engine used during notebook backup restoration. A user with NOTEBOOK_EDITOR permission can inject a VQL query into notebook cell content, which is then evaluated with elevated permissions upon backup restoration. Join the discussion | CVE Database V5 | 09/10/2026, 03:00:00 UTC Added: 09/10/2026, 03:07:53 UTC |
0 A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered into importing a malicious dashboard. When the victim views or imports the dashboard, the payload executes in their browser context, allowing the attacker to modify application data or disrupt application availability. Join the discussion | CVE Database V5 | 09/08/2026, 13:50:31 UTC Added: 09/08/2026, 14:07:44 UTC |
0 Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. Join the discussion | CVE Database V5 | 09/07/2026, 20:17:16 UTC Added: 09/07/2026, 20:22:50 UTC |
0 Twig versions from 1.0.0 up to but not including 3.27.0 contain a vulnerability where the SecurityPolicy::checkMethodAllowed() function unconditionally allows all method calls on instances of Twig\Markup and its subclasses. This flaw allows sandboxed templates to access every public method of Markup-derived objects, bypassing configured method restrictions. The issue was fixed in version 3.27.0. Join the discussion | CVE Database V5 | 09/04/2026, 22:07:35 UTC Added: 09/04/2026, 22:23:48 UTC |
0 Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file. Join the discussion | CVE Database V5 | 09/04/2026, 17:05:09 UTC Added: 09/04/2026, 17:22:56 UTC |
0 IBM Verify Identity Access Advanced Access Control versions 10.0.0 and 11.0.0 contain a vulnerability classified as CWE-1336, involving improper neutralization of special elements used in a template engine. This flaw may allow an attacker to perform an information disclosure attack. The vulnerability has a high severity rating with a CVSS score of 7.5, indicating it can be exploited remotely without privileges or user interaction, resulting in high confidentiality impact but no integrity or availability impact. No patch or remediation details are currently provided. Join the discussion | CVE Database V5 | 09/04/2026, 16:46:39 UTC Added: 09/04/2026, 16:52:46 UTC |
Showing 1 to 10 of 133 results