VendorsSymfonytwigall versions
Vulnerabilities

Symfony Twig

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2026-24425
Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface
Published 2026-05-20 · Analyzed
9.9EPSS 0.008
CVE-2022-23614
Code injection in Twig
Published 2022-02-04 · Modified
9.8EPSS 0.082
CVE-2018-13818
Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it
Published 2018-07-10 · Modified
9.8EPSS 0.069
CVE-2026-46633
Twig: PHP code injection via `{% use %}` template name
Published 2026-07-14 · Analyzed
9.8EPSS 0.007
CVE-2026-46634
Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
Published 2026-07-14 · Analyzed
9.8EPSS 0.006
CVE-2026-48805
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
Published 2026-07-14 · Analyzed
9.1EPSS 0.005
CVE-2026-48806
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
Published 2026-07-14 · Analyzed
9.1EPSS 0.004
CVE-2026-48807
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
Published 2026-07-14 · Analyzed
9.1EPSS 0.004
CVE-2026-46640
Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
Published 2026-07-14 · Analyzed
8.8EPSS 0.006
CVE-2024-45411
Twig has a possible sandbox bypass
Published 2024-09-09 · Modified
8.6EPSS 0.008
CVE-2026-49981
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
Published 2026-07-14 · Analyzed
8.2EPSS 0.004
CVE-2026-46638
Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
Published 2026-07-14 · Analyzed
8.1EPSS 0.005
CVE-2022-39261
Twig may load a template outside a configured directory when using the filesystem loader
Published 2022-09-28 · Modified
7.5EPSS 0.026
CVE-2001-1537
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
Published 2005-07-14 · Modified
7.5EPSS 0.011
CVE-2026-48808
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Published 2026-07-14 · Analyzed
7.5EPSS 0.004
CVE-2026-46627
Twig: Sandbox resource exhaustion via unbounded `for` / `range()`
Published 2026-07-14 · Analyzed
7.1EPSS 0.005
CVE-2026-47732
Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
Published 2026-07-14 · Analyzed
7.1EPSS 0.004
CVE-2026-46639
Twig: Sandbox property and method bypass via object-destructuring assignment
Published 2026-07-14 · Analyzed
7.1EPSS 0.004
CVE-2015-7809
The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.
Published 2015-11-06 · Modified
6.8EPSS 0.034
CVE-2026-46629
Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments
Published 2026-07-14 · Analyzed
6.5EPSS 0.005
CVE-2026-46637
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
Published 2026-07-14 · Analyzed
5.4EPSS 0.003
CVE-2026-46628
Twig: The `spaceless` filter implicitly marks its output as safe
Published 2026-07-14 · Analyzed
5.4EPSS 0.003
CVE-2026-47730
Twig: XSS in profiler HtmlDumper via unescaped template and profile names
Published 2026-07-14 · Analyzed
5.4EPSS 0.003
CVE-2026-46635
Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
Published 2026-07-14 · Analyzed
5.3EPSS 0.003
CVE-2019-9942
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
Published 2019-03-23 · Modified
4.3EPSS 0.014