Twig

Twigphp · 25 CVEs

CVE-2026-46636
HIGH

Twig: Sandbox method allowlist bypass via `Markup` subclass

Sep 4, 2026

CVE-2026-48807
HIGH

Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters

Jul 14, 2026

CVE-2026-48806
HIGH

Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys

Jul 14, 2026

CVE-2026-48808
MEDIUM

Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`

Jul 14, 2026

CVE-2026-48805
MEDIUM

Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`

Jul 14, 2026

CVE-2026-49981
HIGH

Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Templ…

Jul 14, 2026

CVE-2026-46637
MEDIUM

Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`

Jul 14, 2026

CVE-2026-46638
MEDIUM

Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)

Jul 14, 2026

CVE-2026-46640
HIGH

Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation

Jul 14, 2026

CVE-2026-46629
MEDIUM

Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments

Jul 14, 2026

CVE-2026-47730
MEDIUM

Twig: XSS in profiler HtmlDumper via unescaped template and profile names

Jul 14, 2026

CVE-2026-46628
MEDIUM

Twig: The `spaceless` filter implicitly marks its output as safe

Jul 14, 2026

CVE-2026-46634
HIGH

Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name

Jul 14, 2026

CVE-2026-46627
HIGH

Twig: Sandbox resource exhaustion via unbounded `for` / `range()`

Jul 14, 2026

CVE-2026-46633
CRITICAL

Twig: PHP code injection via `{% use %}` template name

Jul 14, 2026

CVE-2026-46639
HIGH

Twig: Sandbox property and method bypass via object-destructuring assignment

Jul 14, 2026

CVE-2026-46635
MEDIUM

Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)

Jul 14, 2026

CVE-2026-47732
HIGH

Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points

Jul 14, 2026

CVE-2026-24425
HIGH

Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface

May 20, 2026

CVE-2025-24374
MEDIUM

Twig fixes a security issue where escaping was missing when using null coalesce operator (??)

Jan 29, 2025

CVE-2024-51754
LOW

Unguarded calls to __toString() when nesting an object into an array in Twig

Nov 6, 2024

CVE-2024-51755
LOW

Unguarded calls to __isset() and to array-accesses when the sandbox is enabled in Twig

Nov 6, 2024

CVE-2024-45411
MEDIUM

Twig has a possible sandbox bypass

Sep 9, 2024

CVE-2022-39261
HIGH

Twig may load a template outside a configured directory when using the filesystem loader

Sep 28, 2022

CVE-2022-23614
CRITICAL

Code injection in Twig

Feb 4, 2022

Showing 1 to 25 of 25 CVEs