⤷ Title: Bug Bounty Hunting: Web Vulnerability (Template Injection)
════════════════════════
𐀪 Author: Muhammad Abdullah Niazi
════════════════════════
ⴵ Time: Wed, 12 Feb 2025 11:36:21 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #template_injection #bug_bounty_hunter #bug_bounty #bug_bounty_program
════════════════════════
𐀪 Author: Muhammad Abdullah Niazi
════════════════════════
ⴵ Time: Wed, 12 Feb 2025 11:36:21 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #template_injection #bug_bounty_hunter #bug_bounty #bug_bounty_program
Medium
Bug Bounty Hunting: Web Vulnerability (Template Injection)
Mastering TI: Techniques, Bypasses, and Exploits
⤷ Title: TInjA: CLI tool for testing web pages for template injection vulnerabilities
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 15 Mar 2025 01:41:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #template injection vulnerabilities
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 15 Mar 2025 01:41:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #template injection vulnerabilities
Penetration Testing Tools
TInjA: CLI tool for testing web pages for template injection vulnerabilities
TInjA is a CLI tool for testing web pages for template injection vulnerabilities. It supports 44 of the most relevant template engines
⤷ Title: Easy $300: Template Injection
════════════════════════
𐀪 Author: Abhijeet Kumawat
════════════════════════
ⴵ Time: Tue, 01 Apr 2025 16:16:44 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty #template_injection #hacking #cybersecurity
════════════════════════
𐀪 Author: Abhijeet Kumawat
════════════════════════
ⴵ Time: Tue, 01 Apr 2025 16:16:44 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty #template_injection #hacking #cybersecurity
Medium
💵Easy $300: Template Injection
In this blog, I’ll walk you through Template Injection, a critical web vulnerability that can lead to data theft, remote code execution…
⤷ Title: Easy $300: Template Injection
════════════════════════
𐀪 Author: Abhijeet Kumawat
════════════════════════
ⴵ Time: Fri, 04 Apr 2025 09:46:22 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty #template_injection #hacking #cybersecurity
════════════════════════
𐀪 Author: Abhijeet Kumawat
════════════════════════
ⴵ Time: Fri, 04 Apr 2025 09:46:22 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty #template_injection #hacking #cybersecurity
Medium
💵Easy $300: Template Injection
In this blog, I’ll walk you through Template Injection, a critical web vulnerability that can lead to data theft, remote code execution…
⤷ Title: PortSwigger — Server-side template injection (SSTI)
════════════════════════
𐀪 Author: Rza Shirinov
════════════════════════
ⴵ Time: Mon, 07 Apr 2025 00:53:35 GMT
════════════════════════
⌗ Tags: #ssti #hacking #portswigger #template_injection #burpsuite
════════════════════════
𐀪 Author: Rza Shirinov
════════════════════════
ⴵ Time: Mon, 07 Apr 2025 00:53:35 GMT
════════════════════════
⌗ Tags: #ssti #hacking #portswigger #template_injection #burpsuite
Medium
PortSwigger — Server-side template injection (SSTI)
Understanding SSTI
⤷ Title: CVE-2025-1087: Critical Template Injection in Insomnia API Client Enables Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 May 2025 00:42:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #API security #CVE_2025_1087 #Developer Tools #Insomnia #JavaScript RCE #Kong #Template Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 May 2025 00:42:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #API security #CVE_2025_1087 #Developer Tools #Insomnia #JavaScript RCE #Kong #Template Injection
Daily CyberSecurity
CVE-2025-1087: Critical Template Injection in Insomnia API Client Enables Remote Code Execution
CVE-2025-1087: Critical flaw in Kong Insomnia allows template injection and arbitrary code execution. Users urged to update to v11.0.2 immediately.
⤷ Title: Exploiting Server-Side Template Injection (SSTI) in Jinja2: From Input Field to Remote Code…
════════════════════════
𐀪 Author: Santhosh Adiga U
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 20:52:53 GMT
════════════════════════
⌗ Tags: #ethical_hacking #injection_vulnerabilities #template_injection #ssti #penetration_testing
════════════════════════
𐀪 Author: Santhosh Adiga U
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 20:52:53 GMT
════════════════════════
⌗ Tags: #ethical_hacking #injection_vulnerabilities #template_injection #ssti #penetration_testing
Medium
Exploiting Server-Side Template Injection (SSTI) in Jinja2: From Input Field to Remote Code Execution
A practical journey into escaping Python sandboxes and taking over the server on target.com
⤷ Title: Server-side Template Injection in an Unknown Language with a Documented Exploit
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sun, 17 Aug 2025 05:05:23 GMT
════════════════════════
⌗ Tags: #ssti_attack #template_injection #bug_bounty #ssti #handlebars_template
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sun, 17 Aug 2025 05:05:23 GMT
════════════════════════
⌗ Tags: #ssti_attack #template_injection #bug_bounty #ssti #handlebars_template
Medium
Server-side Template Injection in an Unknown Language with a Documented Exploit
Discover how attackers identify unknown template engines, leverage documented exploits, and escalate to remote code execution.
⤷ Title: Server-side Template Injection with a Custom Exploit in PHP Twig
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 08:28:27 GMT
════════════════════════
⌗ Tags: #ssti #template_injection #bug_bounty #php_twig #ssti_exploitation
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 08:28:27 GMT
════════════════════════
⌗ Tags: #ssti #template_injection #bug_bounty #php_twig #ssti_exploitation
Medium
Server-side Template Injection with a Custom Exploit in PHP Twig
Discover how server-side template injection (SSTI) can be exploited to delete critical files like SSH keys.
⤷ Title: Server-side Template Injection with a Custom Exploit in PHP Twig
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 19:50:35 GMT
════════════════════════
⌗ Tags: #ssti #template_injection #bug_bounty #php_twig #ssti_exploitation
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 19:50:35 GMT
════════════════════════
⌗ Tags: #ssti #template_injection #bug_bounty #php_twig #ssti_exploitation
Medium
Server-side Template Injection with a Custom Exploit in PHP Twig
Discover how server-side template injection (SSTI) can be exploited to delete critical files like SSH keys.
⤷ Title: Critical Elastic Cloud Flaw: CVE-2025-37729 (CVSS 9.1) Allows RCE via Jinjava Template Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Oct 2025 01:33:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_37729 #ECE #Elastic #Elastic Cloud Enterprise #Jinjava #rce #Template Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Oct 2025 01:33:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_37729 #ECE #Elastic #Elastic Cloud Enterprise #Jinjava #rce #Template Injection
Daily CyberSecurity
Critical Elastic Cloud Flaw: CVE-2025-37729 (CVSS 9.1) Allows RCE via Jinjava Template Injection
A Critical (CVSS 9.1) flaw (CVE-2025-37729) in Elastic Cloud Enterprise allows authenticated Admin RCE. Attackers exploit Jinjava template injection to exfiltrate data and execute commands.
⤷ Title: Advanced Template Injection Lifecycle From Input Vector Discovery to Command Execution and Post…
════════════════════════
𐀪 Author: Kiza
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 03:01:01 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_bounty #tryhackme #template_injection
════════════════════════
𐀪 Author: Kiza
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 03:01:01 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_bounty #tryhackme #template_injection
Medium
Advanced Template Injection Lifecycle From Input Vector Discovery to Command Execution and Post Exploit Enumeration
Author: https://kiza.online/
⤷ Title: CVE-2026-1868: Critical GitLab Gateway Flaw (CVSS 9.9) Allows RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 08 Feb 2026 07:26:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Gateway #CVE_2026_1868 #CVSS 9.9 #DevSecOps #Duo Workflow #gitlab #Patch Alert #Remote Code Execution #Self_Hosted #Template Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 08 Feb 2026 07:26:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Gateway #CVE_2026_1868 #CVSS 9.9 #DevSecOps #Duo Workflow #gitlab #Patch Alert #Remote Code Execution #Self_Hosted #Template Injection
Daily CyberSecurity
CVE-2026-1868: Critical GitLab Gateway Flaw (CVSS 9.9) Allows RCE
GitLab patches critical flaw CVE-2026-1868 (CVSS 9.9) in self-hosted AI Gateway. Vulnerability allows RCE via insecure templates. Update to v18.8.1 now.
⤷ Title: FOSSBilling Template Injection Flaw Exploited in the Wild
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 08:11:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_28496 #FOSSBilling #Remote Code Execution #ssti #Template Injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 08:11:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_28496 #FOSSBilling #Remote Code Execution #ssti #Template Injection
Daily CyberSecurity
FOSSBilling Template Injection Flaw Exploited in the Wild
A FOSSBilling template injection flaw (CVE-2026-28496, CVSS 9.4) is exploited in the wild. Patch to 0.8.0 now to stop server-side template injection.
⤷ Title: TryHackMe | Hacker Holidays — The Byte Lotus Hotel: Day 7| Do Not Disturb Walkthrough
════════════════════════
𐀪 Author: BlackCat53
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 11:37:20 GMT
════════════════════════
⌗ Tags: #template_injection #tryhackme #tryhackme_walkthrough #nosql #sql_injection
════════════════════════
𐀪 Author: BlackCat53
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 11:37:20 GMT
════════════════════════
⌗ Tags: #template_injection #tryhackme #tryhackme_walkthrough #nosql #sql_injection
Medium
TryHackMe | Hacker Holidays — The Byte Lotus Hotel: Day 7| Do Not Disturb Walkthrough
URL to the room: https://tryhackme.com/room/hh-donotdisturb-84a45644