#Template Injection
All CosmicBytez Labs articles tagged #Template Injection, across news, security advisories, how-to guides, and projects.
- Security
Scriban .NET Template Engine Access-Modifier Bypass — CVE-2026-73061
Scriban's TypedObjectAccessor fails to enforce setter visibility, letting template code write private and init-only .NET properties (CVSS 9.8 Critical).
- Security
CVE-2026-73043: SiYuan RCE via Template Calculation Operator
Critical RCE in SiYuan note-taking app. Unsanitized Go templates allow script injection for all versions before v3.7.4.
- Security
CVE-2026-9558: Critical SSTI in Mautic Enables Authenticated RCE
A Server-Side Template Injection flaw in Mautic's Twig-based theme engine allows authenticated users with theme upload permissions to execute arbitrary...
- Security
CVE-2026-41258: OpenMRS Velocity Template Injection Enables
A critical unsandboxed Apache Velocity template injection vulnerability in OpenMRS Core allows authenticated attackers to execute arbitrary code on the...
- Security
CVE-2026-26026: GLPI Template Injection Enables
GLPI versions 11.0.0 through 11.0.5 contain a server-side template injection vulnerability in the administrator interface that allows authenticated admins...