CVE-2026-71880
Server-side template injection in Integrated Publishing Toolkit
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via template injection
| CWE | CWE-1336 |
| Vendor | gbif |
| Product | integrated publishing toolkit |
| Published | Aug 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for gbif integrated publishing toolkit
Be the first to know when new unknown vulnerabilities affecting gbif integrated publishing toolkit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
GBIF / Integrated Publishing Toolkit
0 < 3.3.4