Weaknesses of type CWE-1336

257 results

Divulgação de Informações

É quando a aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais, caminhos internos) para quem não deveria acessá-los. Pode acontecer por erro de configuração, logs verbosos, mensagens de erro detalhadas, ou armazenamento inadequado. O risco é que um atacante consiga informações que facilitem outros ataques.

Example

Um servidor Node.js em produção deixando debug mode ativo, que retorna stack traces completos nas respostas de erro (incluindo caminhos absolutos e variáveis de ambiente), ou um endpoint de recuperação de senha que retorna 'email encontrado' vs 'email não encontrado', revelando quais usuários existem no sistema.

How to mitigate

Desabilite modo debug/verbose em produção; sanitize mensagens de erro para consumidor final (log detalhes internamente, não exponha ao usuário); remova metadados sensíveis de respostas HTTP; aplique princípio do menor privilégio em configurações de acesso a arquivos; nunca exporte credenciais ou chaves em logs ou comentários de código.

CVE-2025-49142MEDIUMNautobot vulnerable to secrets exposure and data manipulation through Jinja2 templatingEPSS 0.4%CVE-2026-22191MEDIUMBeghelli Sicuro24 SicuroWeb AngularJS Template InjectionEPSS 0.4%CVE-2024-58293HIGHAkaunting 3.1.8 Server-Side Template Injection via Multiple Form FieldsEPSS 0.4%CVE-2026-44916LOWIn OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.EPSS 0.4%CVE-2026-41713HIGHPrompt Injection via Memory Poisoning in PromptChatMemoryAdvisorEPSS 0.4%CVE-2025-66436MEDIUMAn SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext through 15.89.0. The EPSS 0.3%CVE-2025-66435MEDIUMAn SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext through 15.89.0. The funEPSS 0.3%CVE-2025-46699MEDIUMDell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a Template Engine vulEPSS 0.3%CVE-2024-57177HIGHA host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header EPSS 0.3%CVE-2025-9094MEDIUMThingsBoard Add Gateway special elements used in a template engineEPSS 0.3%CVE-2025-66361MEDIUMAn issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPEPSS 0.3%CVE-2026-52796LOWGogs: DoS in rendering issue index patternEPSS 0.3%CVE-2026-9160MEDIUMCSTI in Arma Digital's Website TemplateEPSS 0.3%CVE-2023-47542MEDIUMA improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 EPSS 0.3%CVE-2026-46439HIGHcompliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)EPSS 0.3%CVE-2026-41318MEDIUMAnythingLLM vulnerable to stored DOM XSS in chart caption renderer - LLM-driven prompt injection produces executable HTML via unsanitized renderMarkdown(content.caption) in Chartable componentEPSS 0.3%CVE-2026-71286MEDIUMember-dynamic-render-template Client-Side Template Injection via Unsanitized templateStringEPSS 0.3%CVE-2024-35191MEDIUMverbb/formie Server-Side Template Injection for variable-enabled settingsEPSS 0.3%CVE-2022-47896MEDIUMIn JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.EPSS 0.3%CVE-2026-25731HIGHCalibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML ExportEPSS 0.3%