Weaknesses of type CWE-1336

257 results

Divulgação de Informações

É quando a aplicação expõe dados sensíveis (senhas, tokens, chaves, dados pessoais, caminhos internos) para quem não deveria acessá-los. Pode acontecer por erro de configuração, logs verbosos, mensagens de erro detalhadas, ou armazenamento inadequado. O risco é que um atacante consiga informações que facilitem outros ataques.

Example

Um servidor Node.js em produção deixando debug mode ativo, que retorna stack traces completos nas respostas de erro (incluindo caminhos absolutos e variáveis de ambiente), ou um endpoint de recuperação de senha que retorna 'email encontrado' vs 'email não encontrado', revelando quais usuários existem no sistema.

How to mitigate

Desabilite modo debug/verbose em produção; sanitize mensagens de erro para consumidor final (log detalhes internamente, não exponha ao usuário); remova metadados sensíveis de respostas HTTP; aplique princípio do menor privilégio em configurações de acesso a arquivos; nunca exporte credenciais ou chaves em logs ou comentários de código.

CVE-2023-27995HIGHA improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an auEPSS 1.1%CVE-2026-22244HIGHOpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCEEPSS 1.1%CVE-2025-67843HIGHA Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attacEPSS 1.1%CVE-2024-32406HIGHServer-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code viaEPSS 1.1%CVE-2026-40478CRITICALImproper neutralization of specific syntax patterns for unauthorized expressions in ThymeleafEPSS 1.1%CVE-2023-2259CRITICALImproper Neutralization of Special Elements Used in a Template Engine in alfio-event/alf.ioEPSS 1.1%CVE-2026-28697CRITICALCraft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig TemplatesEPSS 1.1%CVE-2024-37301HIGHdocument-merge-service vulnerable to Remote Code Execution via Server-Side Template InjectionEPSS 1.0%CVE-2023-6709CRITICALImproper Neutralization of Special Elements Used in a Template Engine in mlflow/mlflowEPSS 0.9%CVE-2026-21448HIGHBagisto has Normal & Blind SSTI from low-privilege user when ordering productEPSS 0.9%CVE-2026-25526CRITICALJinJava Bypass through ForTag leads to Arbitrary Java ExecutionEPSS 0.9%CVE-2025-68454MEDIUMCraft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTIEPSS 0.9%CVE-2021-4315MEDIUMNYUCCL psiTurk experiment.py special elements used in a template engineEPSS 0.9%CVE-2025-32461CRITICALwikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are EPSS 0.9%CVE-2025-62369HIGHXibo CMS: Remote Code Execution through module templatesEPSS 0.9%CVE-2025-57811MEDIUMCraft Potential Remote Code Execution via Twig SSTIEPSS 0.9%CVE-2024-42355HIGHShopware vulnerable to Server Side Template Injection in Twig using deprecation silence tagEPSS 0.9%CVE-2024-25624MEDIUMiris-web vulnerable to Server Side Template Injection in reportsEPSS 0.9%CVE-2026-40477CRITICALImproper restriction of the scope of accessible objects in Thymeleaf expressionsEPSS 0.9%CVE-2025-66297HIGHGrav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig InjectionEPSS 0.8%