Vulnerabilities (CVE)

Filtered by CWE-1336
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6709 1 Lfprojects 1 Mlflow 2023-12-13 N/A 8.8 HIGH
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to 2.9.2.
CVE-2022-27662 1 F5 1 Traffix Signaling Delivery Controller 2022-05-13 3.5 LOW 4.8 MEDIUM
On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Template Injection vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows an attacker to execute template language-specific instructions in the context of the server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CVE-2022-0323 1 Mustache Project 1 Mustache 2022-01-27 6.5 MEDIUM 8.8 HIGH
Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.