Robuta

https://advisories.gitlab.com/composer/opencart/opencart/GHSA-j2v2-3784-vr44/ Duplicate Advisory: openCart Server-Side Template Injection (SSTI) vulnerability | GitLab Advisory... GHSA-j2v2-3784-vr44 Duplicate Advisory: openCart Server-Side Template Injection (SSTI) vulnerability: Duplicate Advisory This advisory has been withdrawn... server sidetemplate injectionduplicateadvisoryopencart https://advisories.gitlab.com/composer/getgrav/grav/CVE-2024-28116/ Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypass | GitLab Advisory... CVE-2024-28116 Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypass: Grav CMS is vulnerable to a Server-Side Template Injection (SSTI),... https://www.prweb.com/releases/ssti_new_survey_finds_enthusiastic_bipartisan_support_for_innovation_initiative_designed_to_bolster_u_s_economy/prweb13090276.htm SSTI: New Survey Finds Enthusiastic, Bipartisan Support for Innovation Initiative Designed to... WASHINGTON, D.C. (PRWEB) December 02, 2015 -- Overwhelming majorities of voters across the nation and in key swing states support a comprehensive initiative... support for innovationnew survey https://www.ae.utexas.edu/research/recent-grants/space-strategic-technical-institute-for-in-space-operations-ssti-iso Space Strategic Technical Institute for In-Space Operations (SSTI-ISO) technical institutespacestrategicoperationsssti https://ssti.org/ Home | SSTI ssti https://advisories.gitlab.com/pypi/bentoml/CVE-2026-35044/ BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile Generation | GitLab Advisory Database (GLAD) CVE-2026-35044 BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile Generation: The Dockerfile generation function generate_containerfile() in... https://advisories.gitlab.com/composer/craftcms/cms/CVE-2025-46731/ Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI | GitLab Advisory... CVE-2025-46731 Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI: Craft CMS contains a potential remote code execution... https://advisories.gitlab.com/composer/getgrav/grav/CVE-2024-28119/ Server Side Template Injection (SSTI) via Twig escape handler | GitLab Advisory Database (GLAD) CVE-2024-28119 Server Side Template Injection (SSTI) via Twig escape handler: Due to the unrestricted access to twig extension class from grav context, an... https://advisories.gitlab.com/composer/solspace/craft-freeform/CVE-2025-52122/ The Freeform CraftCMS plugin contains an Server-side template injection (SSTI) vulnerability |... CVE-2025-52122 The Freeform CraftCMS plugin contains an Server-side template injection (SSTI) vulnerability: Freeform 5.0.0 to before 5.10.16, a plugin for... https://advisories.gitlab.com/composer/craftcms/webhooks/CVE-2026-32261/ RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin | GitLab Advisory... CVE-2026-32261 RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin: The Webhooks plugin renders user-supplied template content... https://advisories.gitlab.com/composer/craftcms/cms/CVE-2026-28695/ Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process... CVE-2026-28695 Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process gadget: There is an authenticated admin RCE in... https://fahmifj.github.io/tags/ssti/ Ssti | Ef's log Infosec, CTF write-ups, and other IT related stuff sstieflog https://advisories.gitlab.com/composer/bagisto/bagisto/CVE-2026-21449/ Bagisto is vulnerable to SSTI via name parameters provided by non-admin low-privilege users |... CVE-2026-21449 Bagisto is vulnerable to SSTI via name parameters provided by non-admin low-privilege users: SSTI is possible via first name and last name... https://advisories.gitlab.com/golang/github.com/siyuan-note/siyuan/kernel/CVE-2024-55660/ SiYuan has an SSTI via /api/template/renderSprig | GitLab Advisory Database (GLAD) CVE-2024-55660 SiYuan has an SSTI via /api/template/renderSprig: Siyuan's /api/template/renderSprig endpoint is vulnerable to Server-Side Template Injection... via api https://advisories.gitlab.com/composer/bagisto/bagisto/CVE-2025-62416/ bagisto has Server Side Template Injection (SSTI) in Product Description | GitLab Advisory Database... CVE-2025-62416 bagisto has Server Side Template Injection (SSTI) in Product Description: Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI)... https://advisories.gitlab.com/composer/getgrav/grav/CVE-2024-28118/ Server Side Template Injection (SSTI) | GitLab Advisory Database (GLAD) CVE-2024-28118 Server Side Template Injection (SSTI): Due to the unrestricted access to twig extension class from grav context, an attacker can redefine config... server sidetemplate injectionsstigitlabadvisory https://borelenzo.github.io/stuff/2025/04/26/bypassing-thymeleaf-3.1.3-sandbox.html From SSTI to SSTI to RCE - Bypassing Thymeleaf sandbox = 3.1.3.RELEASE - Testeur de stylos Apr 26, 2025 - Abstract The Thymeleaf release version 3.0.12 came with improvements in its sandboxed evaluation process, by restricting objects creations and static function... https://advisories.gitlab.com/composer/getkirby/cms/CVE-2026-34587/ Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering... CVE-2026-34587 Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering: Kirby provides field types (checkboxes,... https://advisories.gitlab.com/composer/getgrav/grav/GHSA-vj3m-2g9h-vm4p/ Grav has multiple RCE vectors: unsafe unserialize (x3), command injection in git clone, SSTI... GHSA-vj3m-2g9h-vm4p Grav has multiple RCE vectors: unsafe unserialize (x3), command injection in git clone, SSTI blocklist bypass: Multiple RCE vectors were... https://advisories.gitlab.com/composer/getgrav/grav/CVE-2024-28117/ Server Side Template Injection (SSTI) | GitLab Advisory Database (GLAD) CVE-2024-28117 Server Side Template Injection (SSTI): Grav validates accessible functions through the Utils::isDangerousFunction function, but does not impose... server sidetemplate injectionsstigitlabadvisory https://advisories.gitlab.com/pypi/spacy-llm/CVE-2025-25362/ Spacy-LLM Server-Side Template Injection (SSTI) vulnerability | GitLab Advisory Database (GLAD) CVE-2025-25362 Spacy-LLM Server-Side Template Injection (SSTI) vulnerability: A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows... llm servertemplate injection https://www.ssti.mx/ Inicio | SSTI iniciossti https://advisories.gitlab.com/composer/craftcms/cms/CVE-2024-52293/ Craft CMS vulnerable to Potential Remote Code Execution via missing path normalization & Twig SSTI... https://irjci.blogspot.com/2014/08/ssti-conference-sept-14-16-to-highlight.html The Rural Blog: SSTI conference Sept. 14-16 to highlight best practices to spur rural economic... The SSTI Regional Prosperity Through Innovation conference, scheduled from Sept. 14-16 in Chicago, will offer several rural-centric sessi... https://advisories.gitlab.com/maven/org.apache.streampark/streampark/CVE-2024-29178/ Apache StreamPark: FreeMarker SSTI RCE Vulnerability | GitLab Advisory Database (GLAD) CVE-2024-29178 Apache StreamPark: FreeMarker SSTI RCE Vulnerability: On versions before 2.1.4, a user could log in and perform a template injection attack... apachefreemarkersstircevulnerability