Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ssti vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2021-25770
In JetBrains YouTrack prior to 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.
Jetbrains Youtrack
2 Github repositories
9.1
CVSSv3
CVE-2021-46063
MCMS v5.2.5 exists to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
Mingsoft Mcms 5.2.5
3 Github repositories
9.8
CVSSv3
CVE-2021-44618
A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header.
Nystudio107 Seomatic 3.4.12
9.8
CVSSv3
CVE-2019-14965
An issue exists in Frappe Framework 10 through 12 prior to 12.0.4. A server side template injection (SSTI) issue exists.
Frappe Frappe
1 Github repository
7.2
CVSSv3
CVE-2019-19999
Halo prior to 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.
Halo Halo 1.2.0
Halo Halo 1.1.3
Halo Halo
9.8
CVSSv3
CVE-2023-36210
MotoCMS Version 3.4.3 Store Category Template exists to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.
Motocms Motocms 3.4.3
9.8
CVSSv3
CVE-2021-44978
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
Idreamsoft Icms
7.2
CVSSv3
CVE-2021-43097
A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code.
Diyhi Bbs 5.3
9.8
CVSSv3
CVE-2023-30331
An issue in the render function of beetl v3.15.0 allows malicious users to execute server-side template injection (SSTI) via a crafted payload.
Beetl Project Beetl 3.15
9.8
CVSSv3
CVE-2021-31635
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote malicious user to execute arbitrary code via the template function.
Jfinal Jfinal 4.9.08
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-20017
administrator privileges
CVE-2024-36401
CVE-2024-8521
CVE-2024-8247
event management system
CVE-2024-45098
aspera faspex
remote attackers
XSS
mindsdb
angeljudesuarez
CVE-2024-45157
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »