CWE-97Variant

Improper Neutralization of Server-Side Includes (SSI) Within a Web Page

Draft in the CWE catalog · 5 CVEs mapped

5
CVEs mapped
7.8
Median CVSS
What it is

The product generates a web page, but does not neutralize or incorrectly neutralizes user-controllable input that could be interpreted as a server-side include (SSI) directive.

Recent examples
8.7cvss
CVE-2023-53934

Kentico Xperience <= 12.0.98 GetResource Handler Denial of Service

⚡ An attacker can easily send crafted requests to Kentico Xperience's GetResource handler, bringing your services to a grinding halt! Think of it like a delivery service where a malicious person sends an avalanche of fake orders, overwhelming the system and causing real customers to be left out in the cold. Just one poorly validated request can trigger chaos! If exploited, this vulnerability could mean your website becomes unreachable, leaving users frustrated and unable to access your services. In a digital world, that's like locking your doors during peak hours – absolutely devastating for your reputation and bottom line!

HIGH
0%
epss
5.1cvss
CVE-2025-36558

KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication. If an attacker provides the user with a PiCtory URL containing an HTML script as an sso_token, that script will reply to the user and be executed.

MEDIUMno explanation yet
19%
epss
8.5cvss
CVE-2025-35996

KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page

⚡ An authenticated remote attacker only needs to craft a special filename to inject malicious scripts into your client’s browser! Think of it like ordering a pizza with instructions to sprinkle in some extra toppings, but you sneak in a few questionable ingredients that end up on the menu — if the restaurant doesn’t check the order, everyone gets served a slice of trouble! 🍕 With this cross-site scripting (XSS) vulnerability, the attacker could execute harmful scripts in users' browsers, potentially stealing sensitive information or hijacking sessions. It's a serious risk, as it could lead to major data breaches and compromise your users' trust. 😱

HIGH
17%
epss
The record
Technical detail
CWE ID
CWE-97
Abstraction
Variant
Structure
Simple
Status
Draft