
CVE-2026-11104-Python-SSTI-via-Jinja2-attr-Filter-Bypass
PoC exploit for CVE-2026-11104 demonstrating Jinja2 attr filter bypass in Flask, enabling server-side template injection and remote code execution.

PoC exploit for CVE-2026-11104 demonstrating Jinja2 attr filter bypass in Flask, enabling server-side template injection and remote code execution.

Nuclei template for CVE-2026-11561 — Apinizer SSTI / RCE version detection

SSTI Exploit Detector is a tool designed to detect potential Server-Side Template Injection (SSTI) vulnerabilities in web applications.

Analysis and Docker reproduction of CVE-2024-28116 - SSTI with sandbox bypass in Grav CMS

Self-contained Docker lab that reproduces CVE-2025-24893, an unauthenticated SSTI-to-RCE in XWiki SolrSearch, and compares vulnerable vs patched…

A drop-in fix for CVE-2023-29689 - SSTI in PyroCMS, via a custom Twig Sandbox implementation