PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.