<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ssti — PoC Archive</title><link>https://poc.intelseclab.com/tags/ssti/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/ssti/index.xml" rel="self" type="application/rss+xml"/><item><title>Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-47916-invision-community-template-injection-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-47916-invision-community-template-injection-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-47916. Status: Weaponized. Affects: Invision Community, themeeditor front controller (IPS\core\modules\front\system\themeeditor::customCss()). Tags: invision-community, ssti, template-injection, theme-editor, unauthenticated-rce, php, cwe-94, python.</description><category>web</category><category>Critical</category><category>invision-community</category><category>ssti</category><category>template-injection</category><category>theme-editor</category><category>unauthenticated-rce</category><category>php</category><category>cwe-94</category><category>python</category></item><item><title>Crafty Controller Webhook Jinja2 Server-Side Template Injection RCE (CVE-2025-14700)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14700-crafty-controller-ssti-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14700-crafty-controller-ssti-rce/</guid><description>Critical severity (CVSS 9.9) — web · CVE-2025-14700. Status: Weaponized. Affects: Crafty Controller (Minecraft server management panel). Tags: crafty-controller, minecraft, jinja2, ssti, server-side-template-injection, reverse-shell, tornado, xsrf, python, cwe-1336.</description><category>web</category><category>Critical</category><category>crafty-controller</category><category>minecraft</category><category>jinja2</category><category>ssti</category><category>server-side-template-injection</category><category>reverse-shell</category><category>tornado</category><category>xsrf</category><category>python</category><category>cwe-1336</category></item><item><title>Thymeleaf SpEL Injection Remote Code Execution (CVE-2026-41901)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41901-thymeleaf-spel-injection-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-41901-thymeleaf-spel-injection-rce/</guid><description>Critical severity — web · CVE-2026-41901. Status: PoC. Affects: Spring Boot application using Thymeleaf template engine. Tags: thymeleaf, spel-injection, ssti, spring-boot, rce, java, template-injection.</description><category>web</category><category>Critical</category><category>thymeleaf</category><category>spel-injection</category><category>ssti</category><category>spring-boot</category><category>rce</category><category>java</category><category>template-injection</category></item><item><title>Shopware Twig Rendered-View Code Injection Regression (CVE-2026-23498)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23498-shopware-twig-code-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23498-shopware-twig-code-injection/</guid><description>High severity — web · CVE-2026-23498. Status: PoC. Affects: Shopware (shopware/shopware, shopware/core). Tags: shopware, twig, code-injection, ssti, php, cwe-94, regression, template-sandbox-bypass.</description><category>web</category><category>High</category><category>shopware</category><category>twig</category><category>code-injection</category><category>ssti</category><category>php</category><category>cwe-94</category><category>regression</category><category>template-sandbox-bypass</category></item><item><title>Jinjava Server-Side Template Injection to RCE via Jackson ObjectMapper (CVE-2026-25526)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25526-jinjava-ssti-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25526-jinjava-ssti-rce/</guid><description>Critical severity — web · CVE-2026-25526. Status: Weaponized. Affects: Jinjava (HubSpot's Java Jinja-like template engine). Tags: ssti, jinjava, java, jackson, objectmapper, sandbox-escape, rce, deserialization.</description><category>web</category><category>Critical</category><category>ssti</category><category>jinjava</category><category>java</category><category>jackson</category><category>objectmapper</category><category>sandbox-escape</category><category>rce</category><category>deserialization</category></item><item><title>Contact Form by Supsystic &lt;= 1.7.36 Unauthenticated SSTI to RCE (CVE-2026-4257)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4257-supsystic-contact-form-ssti-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4257-supsystic-contact-form-ssti-rce/</guid><description>Critical severity — web · CVE-2026-4257. Status: PoC. Affects: Contact Form by Supsystic (WordPress plugin). Tags: wordpress, contact-form-by-supsystic, ssti, twig, rce, unauthenticated, prefill.</description><category>web</category><category>Critical</category><category>wordpress</category><category>contact-form-by-supsystic</category><category>ssti</category><category>twig</category><category>rce</category><category>unauthenticated</category><category>prefill</category></item><item><title>Apache Solr Velocity Template Injection RCE (CVE-2026-44825)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44825-apache-solr-velocity-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44825-apache-solr-velocity-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-44825. Status: PoC. Affects: Apache Solr (VelocityResponseWriter / wt=velocity). Tags: apache-solr, velocity, ssti, template-injection, rce, java, default-credentials.</description><category>web</category><category>Critical</category><category>apache-solr</category><category>velocity</category><category>ssti</category><category>template-injection</category><category>rce</category><category>java</category><category>default-credentials</category></item><item><title>Confluence SSTI RCE - CVE-2023-22527</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_confluence-ssti-rce-cve-2023-22527/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_confluence-ssti-rce-cve-2023-22527/</guid><description>Critical severity (CVSS 10) — web · CVE-2023-22527. Status: Weaponized. Affects: Atlassian Confluence Data Center and Confluence Server. Tags: RCE, Confluence, SSTI, Freemarker, OGNL, unauthenticated, Java, Atlassian, ransomware.</description><category>web</category><category>Critical</category><category>RCE</category><category>Confluence</category><category>SSTI</category><category>Freemarker</category><category>OGNL</category><category>unauthenticated</category><category>Java</category><category>Atlassian</category><category>ransomware</category></item></channel></rss>