CWE-1336 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-1336 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2024-4040A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 …99.5%심각10.0● 랜섬웨어 캠페인에 사용됨CVE-2024-23692Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vu…99.5%심각9.8● 실제 악용이 확인됨CVE-2026-75650Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engi…3.9%심각10.0CVE-2026-12370ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.6…1.5%높음7.6CVE-2026-90970GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of t…0.9%심각9.9CVE-2026-97359HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload h…0.8%심각10.0CVE-2026-94109openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker tem…0.8%높음8.7CVE-2026-88064Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until…0.6%높음8.8
전체 목록
28건
CVE-2026-92592Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled lice…0.5%높음8.7
CVE-2026-89094Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansio…0.5%심각9.9
CVE-2026-53964Document Merge Service is a document template merge service providing an API to manage templates and merge the…0.5%높음7.2
CVE-2026-91925Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during s…0.5%높음8.7
CVE-2026-52762YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side T…0.4%높음7.1
CVE-2026-73858Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13,…0.4%보통5.3
CVE-2026-102142A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated exp…0.4%높음7.2
CVE-2026-46636Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodA…0.4%높음8.7
CVE-2026-104851fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026…0.3%높음8.8
CVE-2026-84462Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that pro…0.3%높음8.6
CVE-2026-81910Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Un…0.3%보통5.9
CVE-2026-102771A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7. Affected by this issue is the func…0.2%낮음2.0
CVE-2026-103540A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects…0.2%낮음2.1
CVE-2026-75036A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by th…0.2%보통5.3
CVE-2026-19584Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Vel…0.2%높음7.7
CVE-2026-33387A template injection vulnerability was discovered in the Dashboards functionality due to improper validation o…0.2%보통5.1
CVE-2026-9160Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc.…0.2%보통4.3
CVE-2026-13297IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.0.2%미평가
CVE-2026-85654Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.d…0.1%높음7.1
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.