PoC Archive PoC Archive

tag

Ssti

  • CVE-2025-47916 web CRITICAL 10 EPSS 85%

    Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916)

    Invision Community's theme editor exposes a customCss() action on the front-end themeeditor controller (/applications/core/modules/front/system/themeeditor.php) that is reachable without authentication and passes the attacker-supplied content request…

    Patched 2026-07-06
  • CVE-2025-14700 web CRITICAL 9.9

    Crafty Controller Webhook Jinja2 Server-Side Template Injection RCE (CVE-2025-14700)

    Crafty Controller's server Webhook configuration accepts a user-controlled "body" template that is rendered server-side with Jinja2 without sandboxing. An authenticated user can set the webhook body to a Jinja2 expression that escapes the sandbox via…

    Unverified 2026-07-06
  • CVE-2026-41901 web CRITICAL

    Thymeleaf SpEL Injection Remote Code Execution (CVE-2026-41901)

    The PoC reproduces a Spring Expression Language (SpEL) injection in a Thymeleaf-rendered template where user-controlled input is reflected into a template expression context without sanitization. By submitting a crafted SpEL payload such as…

    Patched 2026-07-05
  • CVE-2026-23498 web HIGH

    Shopware Twig Rendered-View Code Injection Regression (CVE-2026-23498)

    Shopware previously fixed CVE-2023-2017 by restricting Twig filters so that only allow-listed functions could be invoked from templates. CVE-2026-23498 is a regression of that fix: the allow-list check was not applied to array- and closure-crafted values…

    Patched 2026-07-05
  • CVE-2026-25526 web CRITICAL

    Jinjava Server-Side Template Injection to RCE via Jackson ObjectMapper (CVE-2026-25526)

    CVE-2026-25526 is a sandbox-escape vulnerability in Jinjava, the Java template engine used by many JVM web applications for user-influenced templating. The PoC shows that Jinjava's rendering context exposes an internal interpreter object (int3rpr3t3r) whose…

    Patched 2026-07-05
  • CVE-2026-4257 web CRITICAL EPSS 41%

    Contact Form by Supsystic <= 1.7.36 Unauthenticated SSTI to RCE (CVE-2026-4257)

    CVE-2026-4257 is an unauthenticated Server-Side Template Injection (SSTI) vulnerability in the "Contact Form by Supsystic" WordPress plugin's prefill functionality (cfsPreFill parameter). A form field value is rendered through the Twig template engine without…

    Unverified 2026-07-05
  • CVE-2026-44825 web CRITICAL 9.8

    Apache Solr Velocity Template Injection RCE (CVE-2026-44825)

    Apache Solr bundles the Apache Velocity template engine as an optional response writer. Solr's VelocityResponseWriter renders user-supplied Velocity templates passed via the wt=velocity query parameter without adequately restricting access to Java reflection…

    Patched 2026-07-05
  • CVE-2023-22527 web CRITICAL 10 KEV Ransomware EPSS 100%

    Confluence SSTI RCE - CVE-2023-22527

    CVE-2023-22527 is a CVSS 10.0 unauthenticated Remote Code Execution vulnerability in Atlassian Confluence Data Center and Server. The vulnerability is a Server-Side Template Injection (SSTI) in the Velocity/Freemarker template engine, reachable via the…

    Patched 2026-05-17