PoC Archive PoC Archive

tag

Template-Injection

Critical
Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916)
CVE-2025-47916· Invision Community, themeeditor front controller (IPS\core\modules\front\system\themeeditor::customCss()) patched
Critical
Thymeleaf SpEL Injection Remote Code Execution (CVE-2026-41901)
CVE-2026-41901· Spring Boot application using Thymeleaf template engine unpatched
Critical
PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)
CVE-2026-36239· PbootCMS unpatched
Critical
Handlebars AST Injection Remote Code Execution — CVE-2026-33937
CVE-2026-33937· Handlebars (Node.js templating engine) patched
Medium
EspoCRM 9.3.3 Stored HTML Injection in Email Notifications — CVE-2026-33657
CVE-2026-33657· EspoCRM 9.3.3 patched
High
BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)
CVE-2026-39387· BoidCMS unpatched
Critical
Apache Solr Velocity Template Injection RCE (CVE-2026-44825)
CVE-2026-44825· Apache Solr (VelocityResponseWriter / wt=velocity) patched