Those are the four that are there for all alerts by default. In doing some testing I recently discovered that basically any detail from the log can also be transferred into the e-mail. This is especially helpful for core alert rulesets, where the %D variable always returns the core server, but the "real" affected machine might be listed in the logs.
There is no list available, and knowing what alerts are available for any particular alert can take some digging, but I'll try and get some instructions in a document within the next day or so. Also, when I get this document created it will be an FYI document only and the capabilities will be unsupported.
As it currently stands, those 4 variables you listed are the only ones available.
Just curious, did you manage to get that document created?
Some more info about this would be very helpfull.
This document hasn't yet been created. I got sidetracked on a few documents that were (correctly) deemed to be more important. I will create it today or tomorrow and respond here when it's made.