Twig
Twigphp · 25 CVEs
Twig: Sandbox method allowlist bypass via `Markup` subclass
Sep 4, 2026
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
Jul 14, 2026
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
Jul 14, 2026
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Jul 14, 2026
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
Jul 14, 2026
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Templ…
Jul 14, 2026
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
Jul 14, 2026
Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
Jul 14, 2026
Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
Jul 14, 2026
Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments
Jul 14, 2026
Twig: XSS in profiler HtmlDumper via unescaped template and profile names
Jul 14, 2026
Twig: The `spaceless` filter implicitly marks its output as safe
Jul 14, 2026
Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
Jul 14, 2026
Twig: Sandbox resource exhaustion via unbounded `for` / `range()`
Jul 14, 2026
Twig: PHP code injection via `{% use %}` template name
Jul 14, 2026
Twig: Sandbox property and method bypass via object-destructuring assignment
Jul 14, 2026
Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
Jul 14, 2026
Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
Jul 14, 2026
Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface
May 20, 2026
Twig fixes a security issue where escaping was missing when using null coalesce operator (??)
Jan 29, 2025
Unguarded calls to __toString() when nesting an object into an array in Twig
Nov 6, 2024
Unguarded calls to __isset() and to array-accesses when the sandbox is enabled in Twig
Nov 6, 2024
Twig has a possible sandbox bypass
Sep 9, 2024
Twig may load a template outside a configured directory when using the filesystem loader
Sep 28, 2022
Code injection in Twig
Feb 4, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-46636 | Twig: Sandbox method allowlist bypass via `Markup` subclass | HIGH | 0.57% | Sep 4, 2026 |
| CVE-2026-48807 | Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters | HIGH | 0.37% | Jul 14, 2026 |
| CVE-2026-48806 | Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys | HIGH | 0.42% | Jul 14, 2026 |
| CVE-2026-48808 | Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface` | MEDIUM | 0.41% | Jul 14, 2026 |
| CVE-2026-48805 | Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php` | MEDIUM | 0.48% | Jul 14, 2026 |
| CVE-2026-49981 | Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template` | HIGH | 0.36% | Jul 14, 2026 |
| CVE-2026-46637 | Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']` | MEDIUM | 0.30% | Jul 14, 2026 |
| CVE-2026-46638 | Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411) | MEDIUM | 0.47% | Jul 14, 2026 |
| CVE-2026-46640 | Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation | HIGH | 0.64% | Jul 14, 2026 |
| CVE-2026-46629 | Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments | MEDIUM | 0.54% | Jul 14, 2026 |
| CVE-2026-47730 | Twig: XSS in profiler HtmlDumper via unescaped template and profile names | MEDIUM | 0.29% | Jul 14, 2026 |
| CVE-2026-46628 | Twig: The `spaceless` filter implicitly marks its output as safe | MEDIUM | 0.29% | Jul 14, 2026 |
| CVE-2026-46634 | Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name | HIGH | 0.62% | Jul 14, 2026 |
| CVE-2026-46627 | Twig: Sandbox resource exhaustion via unbounded `for` / `range()` | HIGH | 0.54% | Jul 14, 2026 |
| CVE-2026-46633 | Twig: PHP code injection via `{% use %}` template name | CRITICAL | 0.69% | Jul 14, 2026 |
| CVE-2026-46639 | Twig: Sandbox property and method bypass via object-destructuring assignment | HIGH | 0.39% | Jul 14, 2026 |
| CVE-2026-46635 | Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects) | MEDIUM | 0.33% | Jul 14, 2026 |
| CVE-2026-47732 | Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points | HIGH | 0.40% | Jul 14, 2026 |
| CVE-2026-24425 | Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface | HIGH | 0.76% | May 20, 2026 |
| CVE-2025-24374 | Twig fixes a security issue where escaping was missing when using null coalesce operator (??) | MEDIUM | 0.29% | Jan 29, 2025 |
| CVE-2024-51754 | Unguarded calls to __toString() when nesting an object into an array in Twig | LOW | 0.43% | Nov 6, 2024 |
| CVE-2024-51755 | Unguarded calls to __isset() and to array-accesses when the sandbox is enabled in Twig | LOW | 0.43% | Nov 6, 2024 |
| CVE-2024-45411 | Twig has a possible sandbox bypass | MEDIUM | 0.85% | Sep 9, 2024 |
| CVE-2022-39261 | Twig may load a template outside a configured directory when using the filesystem loader | HIGH | 3.15% | Sep 28, 2022 |
| CVE-2022-23614 | Code injection in Twig | CRITICAL | 8.21% | Feb 4, 2022 |
Showing 1 to 25 of 25 CVEs