Symfony Twig vulnerabilities
25 known vulnerabilities affecting symfony/twig.
Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH7MEDIUM9LOW1
Vulnerabilities
Page 2 of 2
CVE-2026-46637P4MEDIUMCVSS 5.4fixed in 3.26.02026-07-14
CVE-2026-46637 [MEDIUM] CWE-116 CVE-2026-46637: Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twi
Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.
nvd
CVE-2026-46628P4MEDIUMCVSS 5.4fixed in 3.26.02026-07-14
CVE-2026-46628 [MEDIUM] CWE-116 CVE-2026-46628: Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0.
nvd
CVE-2001-1537P4HIGHCVSS 7.5≤ 2.7.42001-12-31
CVE-2001-1537 [HIGH] CWE-312 CVE-2001-1537: The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleart
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
nvd
CVE-2026-46635P4MEDIUMCVSS 4.3fixed in 3.26.02026-07-14
CVE-2026-46635 [MEDIUM] CWE-863 CVE-2026-46635: Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAllowed(), allowing an untrusted template author with column in allowedFilters to read properties that are not in t
nvd
CVE-2019-9942P4LOWCVSS 3.7fixed in 1.38.0≥ 2.0.0, < 2.7.02019-03-23
CVE-2019-9942 [LOW] CVE-2019-9942: A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under so
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
nvd
← Previous2 / 2