CWE-1336: CWE-1336

60
Total CVEs
24
Critical
27
High
8.4
Avg CVSS

Yearly Trend

2026
15
2025
26
2024
15
2023
2
2022
2

Top Affected Vendors

1 Webkul 4
2 Craftcms 3
3 Getgrav 2
4 Hubspot 2
5 Atlassian 1
6 Vollstart 1
7 Invisioncommunity 1
8 Canonical 1
9 Fedoraproject 1
10 Gibbonedu 1

All CWE-1336 CVEs (60)

CVE-2024-39766
7.0

This SQL injection vulnerability in Intel Neural Compressor allows authenticated local users to execute arbitrary SQL commands, potentially leading to...

Nov 13, 2024
CVE-2026-23626
6.8

This vulnerability allows authenticated users with export permissions in Kimai time-tracking software to deploy malicious Twig templates that bypass s...

Jan 18, 2026
CVE-2025-66361
6.5

Logpoint versions before 7.7.0 expose sensitive information in system processes during high CPU load conditions. This affects all Logpoint deployments...

Nov 28, 2025
CVE-2025-54287
6.5

This vulnerability allows attackers with instance configuration permissions in Canonical LXD to perform template injection when creating instance snap...

Oct 2, 2025
CVE-2026-27629
5.9

InvenTree versions before 1.2.3 have a server-side template injection vulnerability that allows staff users to modify Jinja2 templates for batch code ...

Feb 25, 2026
CVE-2025-35113
5.9

Agiloft Release 28 contains a template injection vulnerability in its EUI template engine that allows authenticated attackers to execute arbitrary cod...

Aug 26, 2025
CVE-2024-35191
4.4

This vulnerability allows authenticated users with form settings access to inject malicious Twig code into form fields like Submission Title or Succes...

May 20, 2024
CVE-2025-46699
4.3

Dell Data Protection Advisor versions before 19.12 contain a template engine injection vulnerability that allows low-privileged remote attackers to ac...

Jan 23, 2026
CVE-2024-58303
N/A

CVE-2024-58303 is a server-side template injection vulnerability in FoF Pretty Mail 1.1.2 that allows administrative users to inject malicious code in...

Dec 11, 2025
CVE-2024-58293
N/A

CVE-2024-58293 is a server-side template injection vulnerability in Akaunting 3.1.8 that allows authenticated administrators to execute template expre...

Dec 11, 2025

About CWE-1336 (CWE-1336)

Our database tracks 60 CVEs classified as CWE-1336, with 24 rated critical and 27 rated high severity. The average CVSS score for CWE-1336 vulnerabilities is 8.4.

External reference: View CWE-1336 on MITRE CWE →

Monitor CWE-1336 Vulnerabilities

Get alerted when new CWE-1336 CVEs affect your infrastructure.

Start Monitoring Free