CVE-2026-28496
FOSSBilling
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnerability in the template rendering system. Administrators with access to features that render Twig templates (email templates, mass mail campaigns, custom payment adapters, and the `string_render` API endpoint) can inject arbitrary Twig expressions, leading to information disclosure and remote code execution. The vulnerability exists because Twig templates are rendered without a sandbox, allowing access to the full Twig environment, API context,...
- CVSS
- 9.4
- EPSS
- 17.6% 96.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.24