CVE-2025-14700
9.9CRITICALAn input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection
Published: 12/17/2025Updated: 12/23/2025
Description
An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.
AI AnalysisPowered by AI
Affected Products
craftycontrolcrafty_controller
4.6.1