Falhas do tipo CWE-1336

254 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, tokens, arquivos internos, estrutura do sistema) a usuários ou atacantes que não deveriam acessá-los. Isso ocorre por falta de controle de acesso adequado, validação insuficiente ou exposição acidental de dados em logs, mensagens de erro ou respostas HTTP.

Exemplo

Um site exibe mensagens de erro detalhadas que revelam caminhos de arquivos e versões de banco de dados; ou uma API retorna dados de outros usuários porque não valida permissões; ou credenciais ficam expostas em comentários do código-fonte publicado.

Como mitigar

Implemente controle de acesso granular (verificar quem acessa o quê); sanitize mensagens de erro (mostrar genéricas ao usuário, logs detalhados apenas internamente); revise e restrinja dados retornados por APIs; escaneie repositórios e logs de produção para credenciais expostas.

CVE-2026-44723MEDIUMVowpal Wabbit: Shell injection via crafted PR title in python_checks.yml allows arbitrary command execution on CI runnerEPSS 0.5%CVE-2025-53909CRITICALmailcow: dockerized vulnerable to SSTI in Quota and Quarantine Notification TemplateEPSS 0.5%CVE-2026-28783CRITICALCraft has a Twig Function Blocklist BypassEPSS 0.5%CVE-2025-60355CRITICALzhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.EPSS 0.5%CVE-2026-82447HIGHSkyvern before 1.0.45 Sandbox Escape via TextPromptBlockEPSS 0.5%CVE-2026-23626MEDIUMKimai Vulnerable to Authenticated Server-Side Template Injection (SSTI)EPSS 0.5%CVE-2026-13051CRITICALForm::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext templateEPSS 0.5%CVE-2025-14731MEDIUMCTCMS Content Management System Frontend/Template Management CT_Parser.php special elements used in a template engineEPSS 0.4%CVE-2024-54954HIGHOneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.EPSS 0.4%CVE-2026-52762HIGHYesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic TemplatesEPSS 0.4%CVE-2026-54653HIGH`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema fieldEPSS 0.4%CVE-2026-45312CRITICALRAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code ExecutionEPSS 0.4%CVE-2026-77939HIGHFlextype CMS 1.0.0-dev RCE via POST /api/v1/query EndpointEPSS 0.4%CVE-2025-3841MEDIUMwix-incubator jam Jinja2 Template jam.py special elements used in a template engineEPSS 0.4%CVE-2025-10380HIGHAdvanced Views – Display Posts, Custom Fields, and More <= 3.7.19 - Authenticated (Author+) Remote Code Execution via SSTIEPSS 0.4%CVE-2024-27623MEDIUMCMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, pEPSS 0.4%CVE-2025-35113MEDIUMAgiloft improper neutralization in EUI template engineEPSS 0.4%CVE-2026-47727HIGHTrilium: RCE via `shareTemplate` relation missing `isDangerous` flag — Safe import bypass leading to EJS SSTI (Incomplete Fix of CVE-2026-45668)EPSS 0.4%CVE-2026-41065HIGHTautulli Vulnerable to Unauthenticated/Authenticated Remote Code Execution via Newsletter Custom Template DirectoryEPSS 0.4%CVE-2026-41901CRITICALThymeleaf: Improper recognition of unauthorized syntax patterns in sandboxed Thymeleaf expressionsEPSS 0.4%