PoC Archive PoC Archive

tag

Template-Injection

Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916) EPSS 84%
CVE-2025-47916 web Patched
CVE-2025-47916webCRITICAL 10Patched2026-07-06Thymeleaf SpEL Injection Remote Code Execution (CVE-2026-41901)
CVE-2026-41901 web Patched
CVE-2026-41901webCRITICALPatched2026-07-05PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)
CVE-2026-36239 web Unverified
CVE-2026-36239webCRITICALUnverified2026-07-05Handlebars AST Injection Remote Code Execution — CVE-2026-33937
CVE-2026-33937 web Patched
CVE-2026-33937webCRITICALPatched2026-07-05EspoCRM 9.3.3 Stored HTML Injection in Email Notifications — CVE-2026-33657
CVE-2026-33657 web Patched
CVE-2026-33657webMEDIUMPatched2026-07-05BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)
CVE-2026-39387 web Patched
CVE-2026-39387webHIGHPatched2026-07-05Apache Solr Velocity Template Injection RCE (CVE-2026-44825)
CVE-2026-44825 web Patched
CVE-2026-44825webCRITICAL 9.8Patched2026-07-05