Template authors could inject php code by choosing a malicious {block} name or {include} file name. (CVE-2022-29221)
{ "section": "core" }