Every CVE whose affected-product data names Symfony Twig, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (25)
CVE-2026-46633 — CVSS 9.8 (critical): Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use…
CVE-2018-13818 — CVSS 9.8 (critical): Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig…
CVE-2026-46634 — CVSS 9.8 (critical): Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized…
CVE-2026-48805 — CVSS 9.1 (critical): Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current…
CVE-2026-48806 — CVSS 9.1 (critical): Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings…
CVE-2026-48807 — CVSS 9.1 (critical): Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join…
CVE-2026-46640 — CVSS 8.8 (high): Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate…
CVE-2022-23614 — CVSS 8.8 (high): Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to…
CVE-2026-24425 — CVSS 8.8 (high): Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows…
CVE-2024-45411 — CVSS 8.5 (high): Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed…
CVE-2026-49981 — CVSS 8.2 (high): Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a…
CVE-2026-46638 — CVSS 8.1 (high): Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside…
CVE-2001-1537 — CVSS 7.5 (high): The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies…
CVE-2026-48808 — CVSS 7.5 (high): Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward…
CVE-2022-39261 — CVSS 7.5 (high): Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the…
CVE-2015-7809 — CVSS 6.8 (medium): The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute…
CVE-2026-46629 — CVSS 6.5 (medium): Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays…
CVE-2026-46639 — CVSS 6.5 (medium): Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with…
CVE-2026-46627 — CVSS 6.5 (medium): Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or…
CVE-2026-47732 — CVSS 6.5 (medium): Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand…
CVE-2026-47730 — CVSS 5.4 (medium): Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and…
CVE-2026-46637 — CVSS 5.4 (medium): Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with…
CVE-2026-46628 — CVSS 5.4 (medium): Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig…
CVE-2026-46635 — CVSS 4.3 (medium): Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and…
CVE-2019-9942 — CVSS 3.7 (low): A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to…