Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: twig Clear
ID Title
CVE-2026-46627 Vulnerability in symfony (CVE-2026-46627)
vulnerability in symfony (CVE-2026-46627). Risk of unauthorized operations or information disclosure.
CVE-2026-49981 Vulnerability in twig/twig (CVE-2026-49981)
vulnerability in twig/twig (CVE-2026-49981). Confidential information can be exposed externally. Exploitable via ``Template``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-48808 Vulnerability in twig/twig (CVE-2026-48808)
vulnerability in twig/twig (CVE-2026-48808). Confidential information can be exposed externally. Exploitable via ``SourcePolicyInterface``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-48807 Vulnerability in twig/twig (CVE-2026-48807)
vulnerability in twig/twig (CVE-2026-48807). Confidential information can be exposed externally. Exploitable via ``Traversable``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-48806 Vulnerability in twig/twig (CVE-2026-48806)
vulnerability in twig/twig (CVE-2026-48806). Confidential information can be exposed externally. Exploitable via ``CheckToStringNode``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-48805 Vulnerability in twig/twig (CVE-2026-48805)
vulnerability in twig/twig (CVE-2026-48805). Confidential information can be exposed externally. Exploitable via ``Environment``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-47732 Authorization Flaw in twig/twig (CVE-2026-47732)
vulnerability in twig/twig (CVE-2026-47732). Confidential information can be exposed externally. Exploitable via ``SandboxNodeVisitor``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-47730 Cross-Site Scripting (XSS) in twig/twig (CVE-2026-47730)
cross-site scripting in twig/twig (CVE-2026-47730). Risk of unauthorized operations or information disclosure. Exploitable via ``ArrayLoader``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-46640 Code Injection in twig/twig (CVE-2026-46640)
code injection in twig/twig (CVE-2026-46640). Successful exploitation can lead to full system takeover. Exploitable via ``_self``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-46639 Vulnerability in twig/twig (CVE-2026-46639)
vulnerability in twig/twig (CVE-2026-46639). Confidential information can be exposed externally. Exploitable via ``false``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-46638 Vulnerability in twig/twig (CVE-2026-46638)
vulnerability in twig/twig (CVE-2026-46638). Confidential information can be exposed externally. Exploitable via ``Environment``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-46637 Vulnerability in twig/markdown-extra (CVE-2026-46637)
vulnerability in twig/markdown-extra (CVE-2026-46637). Risk of unauthorized operations or information disclosure. Exploitable via ``html``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-46635 Authorization Flaw in twig/twig (CVE-2026-46635)
vulnerability in twig/twig (CVE-2026-46635). Risk of unauthorized operations or information disclosure. Exploitable via ``column``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-46634 Vulnerability in twig/twig (CVE-2026-46634)
vulnerability in twig/twig (CVE-2026-46634). Successful exploitation can lead to full system takeover. Exploitable via ``SourcePolicyInterface``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-46633 Code Injection in twig/twig (CVE-2026-46633)
code injection in twig/twig (CVE-2026-46633). Successful exploitation can lead to full system takeover. Exploitable via ``SecurityPolicy``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-46629 Vulnerability in twig/intl-extra (CVE-2026-46629)
vulnerability in twig/intl-extra (CVE-2026-46629). Risk of unauthorized operations or information disclosure. Exploitable via ``IntlExtension``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-46628 Vulnerability in twig/twig (CVE-2026-46628)
vulnerability in twig/twig (CVE-2026-46628). Risk of unauthorized operations or information disclosure. Exploitable via ``spaceless``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-24425 Vulnerability in twig/twig (CVE-2026-24425)
vulnerability in twig/twig (CVE-2026-24425). Successful exploitation can lead to full system takeover. Exploitable via ``SourcePolicyInterface``. Mitigation: upgrade to `3.26.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →