https://advisories.gitlab.com/composer/opencart/opencart/GHSA-j2v2-3784-vr44/
Duplicate Advisory: openCart Server-Side Template Injection (SSTI) vulnerability | GitLab Advisory...
GHSA-j2v2-3784-vr44 Duplicate Advisory: openCart Server-Side Template Injection (SSTI) vulnerability: Duplicate Advisory This advisory has been withdrawn...
server sidetemplate injectionduplicateadvisoryopencart
https://advisories.gitlab.com/composer/getgrav/grav/CVE-2024-28116/
Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypass | GitLab Advisory...
CVE-2024-28116 Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypass: Grav CMS is vulnerable to a Server-Side Template Injection (SSTI),...
https://www.prweb.com/releases/ssti_new_survey_finds_enthusiastic_bipartisan_support_for_innovation_initiative_designed_to_bolster_u_s_economy/prweb13090276.htm
SSTI: New Survey Finds Enthusiastic, Bipartisan Support for Innovation Initiative Designed to...
WASHINGTON, D.C. (PRWEB) December 02, 2015 -- Overwhelming majorities of voters across the nation and in key swing states support a comprehensive initiative...
support for innovationnew survey
https://www.ae.utexas.edu/research/recent-grants/space-strategic-technical-institute-for-in-space-operations-ssti-iso
Space Strategic Technical Institute for In-Space Operations (SSTI-ISO)
technical institutespacestrategicoperationsssti
https://ssti.org/
Home | SSTI
ssti
https://advisories.gitlab.com/pypi/bentoml/CVE-2026-35044/
BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile Generation | GitLab Advisory Database (GLAD)
CVE-2026-35044 BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile Generation: The Dockerfile generation function generate_containerfile() in...
https://advisories.gitlab.com/composer/craftcms/cms/CVE-2025-46731/
Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI | GitLab Advisory...
CVE-2025-46731 Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI: Craft CMS contains a potential remote code execution...
https://advisories.gitlab.com/composer/getgrav/grav/CVE-2024-28119/
Server Side Template Injection (SSTI) via Twig escape handler | GitLab Advisory Database (GLAD)
CVE-2024-28119 Server Side Template Injection (SSTI) via Twig escape handler: Due to the unrestricted access to twig extension class from grav context, an...
https://advisories.gitlab.com/composer/solspace/craft-freeform/CVE-2025-52122/
The Freeform CraftCMS plugin contains an Server-side template injection (SSTI) vulnerability |...
CVE-2025-52122 The Freeform CraftCMS plugin contains an Server-side template injection (SSTI) vulnerability: Freeform 5.0.0 to before 5.10.16, a plugin for...
https://advisories.gitlab.com/composer/craftcms/webhooks/CVE-2026-32261/
RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin | GitLab Advisory...
CVE-2026-32261 RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin: The Webhooks plugin renders user-supplied template content...
https://advisories.gitlab.com/composer/craftcms/cms/CVE-2026-28695/
Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process...
CVE-2026-28695 Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process gadget: There is an authenticated admin RCE in...
https://fahmifj.github.io/tags/ssti/
Ssti | Ef's log
Infosec, CTF write-ups, and other IT related stuff
sstieflog
https://advisories.gitlab.com/composer/bagisto/bagisto/CVE-2026-21449/
Bagisto is vulnerable to SSTI via name parameters provided by non-admin low-privilege users |...
CVE-2026-21449 Bagisto is vulnerable to SSTI via name parameters provided by non-admin low-privilege users: SSTI is possible via first name and last name...
https://advisories.gitlab.com/golang/github.com/siyuan-note/siyuan/kernel/CVE-2024-55660/
SiYuan has an SSTI via /api/template/renderSprig | GitLab Advisory Database (GLAD)
CVE-2024-55660 SiYuan has an SSTI via /api/template/renderSprig: Siyuan's /api/template/renderSprig endpoint is vulnerable to Server-Side Template Injection...
via api
https://advisories.gitlab.com/composer/bagisto/bagisto/CVE-2025-62416/
bagisto has Server Side Template Injection (SSTI) in Product Description | GitLab Advisory Database...
CVE-2025-62416 bagisto has Server Side Template Injection (SSTI) in Product Description: Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI)...
https://advisories.gitlab.com/composer/getgrav/grav/CVE-2024-28118/
Server Side Template Injection (SSTI) | GitLab Advisory Database (GLAD)
CVE-2024-28118 Server Side Template Injection (SSTI): Due to the unrestricted access to twig extension class from grav context, an attacker can redefine config...
server sidetemplate injectionsstigitlabadvisory
https://borelenzo.github.io/stuff/2025/04/26/bypassing-thymeleaf-3.1.3-sandbox.html
From SSTI to SSTI to RCE - Bypassing Thymeleaf sandbox = 3.1.3.RELEASE - Testeur de stylos
Apr 26, 2025 - Abstract The Thymeleaf release version 3.0.12 came with improvements in its sandboxed evaluation process, by restricting objects creations and static function...
https://advisories.gitlab.com/composer/getkirby/cms/CVE-2026-34587/
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering...
CVE-2026-34587 Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering: Kirby provides field types (checkboxes,...
https://advisories.gitlab.com/composer/getgrav/grav/GHSA-vj3m-2g9h-vm4p/
Grav has multiple RCE vectors: unsafe unserialize (x3), command injection in git clone, SSTI...
GHSA-vj3m-2g9h-vm4p Grav has multiple RCE vectors: unsafe unserialize (x3), command injection in git clone, SSTI blocklist bypass: Multiple RCE vectors were...
https://advisories.gitlab.com/composer/getgrav/grav/CVE-2024-28117/
Server Side Template Injection (SSTI) | GitLab Advisory Database (GLAD)
CVE-2024-28117 Server Side Template Injection (SSTI): Grav validates accessible functions through the Utils::isDangerousFunction function, but does not impose...
server sidetemplate injectionsstigitlabadvisory
https://advisories.gitlab.com/pypi/spacy-llm/CVE-2025-25362/
Spacy-LLM Server-Side Template Injection (SSTI) vulnerability | GitLab Advisory Database (GLAD)
CVE-2025-25362 Spacy-LLM Server-Side Template Injection (SSTI) vulnerability: A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows...
llm servertemplate injection
https://www.ssti.mx/
Inicio | SSTI
iniciossti
https://advisories.gitlab.com/composer/craftcms/cms/CVE-2024-52293/
Craft CMS vulnerable to Potential Remote Code Execution via missing path normalization & Twig SSTI...
https://irjci.blogspot.com/2014/08/ssti-conference-sept-14-16-to-highlight.html
The Rural Blog: SSTI conference Sept. 14-16 to highlight best practices to spur rural economic...
The SSTI Regional Prosperity Through Innovation conference, scheduled from Sept. 14-16 in Chicago, will offer several rural-centric sessi...
https://advisories.gitlab.com/maven/org.apache.streampark/streampark/CVE-2024-29178/
Apache StreamPark: FreeMarker SSTI RCE Vulnerability | GitLab Advisory Database (GLAD)
CVE-2024-29178 Apache StreamPark: FreeMarker SSTI RCE Vulnerability: On versions before 2.1.4, a user could log in and perform a template injection attack...
apachefreemarkersstircevulnerability