boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1336

Weakness type CWE-1336 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
64631

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▃▄█

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 8 · 2026-06 7 · 2026-07 14 · 2026-08 32

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-236929.899.9KEVRejetto HTTP File Server 2.3m Unauthenticated RCE
CVE-2026-284969.496.9FOSSBilling: Server-side template injection in Twig template rendering enables informat…
CVE-2026-7329910.066.1Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core N…
CVE-2026-404779.055.3Improper restriction of the scope of accessible objects in Thymeleaf expressions
CVE-2026-404789.052.7Improper neutralization of specific syntax patterns for unauthorized expressions in Thy…
CVE-2026-715025.150.6Unauthenticated Stored Vue Template Injection Leads to Cross-Site Scripting in CTI-Tran…
CVE-2026-4418110.050.4Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in R…
CVE-2026-157349.849.5WGDashboard Server-Side Template Injection vulnerability
CVE-2026-4832310.047.3Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Te…
CVE-2026-114078.647.2Pimcore CMS 12.3.8 Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
CVE-2026-543909.346.3JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer
CVE-2026-733307.545.5CamaleonCMS 2.9.1 Server-Side Template Injection via test_email Action
CVE-2026-95589.944.7
CVE-2026-659749.944.0ERPNext: Server-Side Template Injection leading to Remote Code Execution
CVE-2026-349069.344.0Server-Side Template Injection (SSTI) in Wirtualna Uczelnia
CVE-2026-691188.743.8Cachet 2.4.1 Authenticated Server-Side Template Injection RCE
CVE-2026-442097.543.1Banks: Critical Remote Code Execution (RCE) via Jinja2 SSTI
CVE-2026-448456.740.9JumpServer: Remote Command Execution (RCE) via Jinja Template Injection in Applet Host …
CVE-2022-49939.139.6HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method disp…
CVE-2026-456979.839.3Formie: Pre-authenticated server-side template injection in Hidden fields

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
orval-labs7
acacode4
frappe3
koxudaxi3
getgrav2
thymeleaf2
verbb2
adobe1
apache1
axway1
bolt1
cachethq1
craftcms1
crocoblock. jetimpex1
djangocrm1