Falhas do tipo CWE-1336

198 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, tokens, arquivos internos, estrutura do sistema) a usuários ou atacantes que não deveriam acessá-los. Isso ocorre por falta de controle de acesso adequado, validação insuficiente ou exposição acidental de dados em logs, mensagens de erro ou respostas HTTP.

Exemplo

Um site exibe mensagens de erro detalhadas que revelam caminhos de arquivos e versões de banco de dados; ou uma API retorna dados de outros usuários porque não valida permissões; ou credenciais ficam expostas em comentários do código-fonte publicado.

Como mitigar

Implemente controle de acesso granular (verificar quem acessa o quê); sanitize mensagens de erro (mostrar genéricas ao usuário, logs detalhados apenas internamente); revise e restrinja dados retornados por APIs; escaneie repositórios e logs de produção para credenciais expostas.

CVE-2024-4040CRITICALUnauthenticated arbitrary file read and remote code execution in CrushFTPEPSS 99.5%KEVCVE-2024-23692CRITICALRejetto HTTP File Server 2.3m Unauthenticated RCEEPSS 99.5%KEVCVE-2025-47916CRITICALInvision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within thEPSS 85.1%CVE-2024-32651CRITICALServer Side Template Injection in Jinja2 allows Remote Command ExecutionEPSS 83.6%CVE-2022-25813Server-Side Template Injection affecting the ecommerce plugin of Apache OFBizEPSS 67.3%CVE-2025-34300CRITICALSawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCEEPSS 51.1%CVE-2024-24724CRITICALGibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution EPSS 26.1%CVE-2024-6386CRITICALWPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template InjectionEPSS 25.5%CVE-2025-49619HIGHSkyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation EPSS 20.6%CVE-2026-28496CRITICALFOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCEEPSS 17.6%CVE-2026-26026CRITICALGLPI has a Server-Side Template Injection via Double-CompilationEPSS 11.3%CVE-2025-53833CRITICALLaRecipe is vulnerable to Server-Side Template Injection attacksEPSS 9.4%CVE-2022-0944CRITICALTemplate injection in connection test endpoint leads to RCE in sqlpad/sqlpadEPSS 8.7%CVE-2025-14700CRITICALImproper Neutralization of Special Elements Used in a Template Engine in Crafty ControllerEPSS 6.2%CVE-2024-28116HIGHServer-Side Template Injection (SSTI) with Grav CMS security sandbox bypassEPSS 5.8%CVE-2023-34448HIGHGrav Server-side Template Injection (SSTI) via Twig Default FiltersEPSS 4.5%CVE-2025-23211CRITICALTandoor Recipes - SSTI - Remote Code ExecutionEPSS 3.5%CVE-2025-66294HIGHGrav is vulnerable to RCE via SSTI through Twig Sandbox BypassEPSS 2.9%CVE-2025-59340CRITICALjinjava Sandbox Bypass via JavaType-Based DeserializationEPSS 2.3%CVE-2025-69516HIGHA Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting verEPSS 2.1%