CVE-2026-47730
published 2026-07-14CVE-2026-47730: Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.29%
22.2th percentile
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| symfony | twig | >= 3.0.0 < 3.26.0 | 3.26.0 |
| twig | twig | >= 3.0.0 < 3.26.0 | 3.26.0 |
| twigphp | twig | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
twigphp Twig Profiler HtmlDumper cross site scripting
vuldb·2026-06-06
CVE-2026-47730 [LOW] twigphp Twig Profiler HtmlDumper cross site scripting
A vulnerability labeled as problematic has been found in twigphp Twig. This vulnerability affects the function HtmlDumper of the component Profiler. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-47730. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
GHSA
Twig: XSS in profiler HtmlDumper via unescaped template and profile names
ghsa·2026-06-05
CVE-2026-47730 [LOW] CWE-79 Twig: XSS in profiler HtmlDumper via unescaped template and profile names
Twig: XSS in profiler HtmlDumper via unescaped template and profile names
### Description
`Twig\Profiler\Dumper\HtmlDumper` writes `Profile::getTemplate()` and `Profile::getName()` straight into its HTML output without escaping:
```php
protected function formatTemplate(Profile $profile, $prefix): string
{
return \sprintf('%s└ %s', $prefix, self::$colors['template'], $profile->getTemplate());
}
```
The template name comes from the loader (the array key for `ArrayLoader`, a row id for a database-backed loader, etc.). When that name is attacker-controlled, the profiler dump emits arbitrary HTML, and any browser that renders it executes the injected markup. This is an output-encoding bug in profiler/debug tooling, not a sandbox escape.
### Resolution
`HtmlDumper` now runs both `Profile::
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-47730 phpMyAdmin: Twig: Cross-site Scripting (XSS) vulnerability in HTML profiler dump [epel-all]
bugzilla·2026-07-15·CVSS 5.1
CVE-2026-47730 [MEDIUM] CVE-2026-47730 phpMyAdmin: Twig: Cross-site Scripting (XSS) vulnerability in HTML profiler dump [epel-all]
CVE-2026-47730 phpMyAdmin: Twig: Cross-site Scripting (XSS) vulnerability in HTML profiler dump [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.
Bugzilla
CVE-2026-47730 phpMyAdmin: Twig: Cross-site Scripting (XSS) vulnerability in HTML profiler dump [fedora-all]
bugzilla·2026-07-15·CVSS 5.1
CVE-2026-47730 [MEDIUM] CVE-2026-47730 phpMyAdmin: Twig: Cross-site Scripting (XSS) vulnerability in HTML profiler dump [fedora-all]
CVE-2026-47730 phpMyAdmin: Twig: Cross-site Scripting (XSS) vulnerability in HTML profiler dump [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.
Bugzilla
CVE-2026-47730 twig/twig: Twig: Cross-site Scripting (XSS) vulnerability in HTML profiler dump
bugzilla·2026-07-14·CVSS 5.1
CVE-2026-47730 [MEDIUM] CVE-2026-47730 twig/twig: Twig: Cross-site Scripting (XSS) vulnerability in HTML profiler dump
CVE-2026-47730 twig/twig: Twig: Cross-site Scripting (XSS) vulnerability in HTML profiler dump
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.
2026-07-14
Published