Twigphp Twig vulnerabilities
24 known vulnerabilities affecting twigphp/twig.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH6MEDIUM9LOW2
Vulnerabilities
Page 1 of 2
CVE-2022-23614P2CRITICALCVSS 9.8v>= 3.0.0, < 3.3.8v>= 2.0.0, < 2.14.112022-02-04
CVE-2022-23614 [CRITICAL] CWE-74 CVE-2022-23614: Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of t
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow call
nvd
CVE-2026-24425P2CRITICALCVSS 9.9≥ 3.9.0, < 3.26.0v2.16.*2026-05-20
CVE-2026-24425 [CRITICAL] CWE-693 CVE-2026-24425: Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a So
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass
nvd
CVE-2026-46636P3HIGHCVSS 8.7v>= 1.0.0, < 3.27.02026-09-04
CVE-2026-46636 [HIGH] CWE-1336 CVE-2026-46636: Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::ch
Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically
nvd
CVE-2026-46633P3CRITICALCVSS 9.8fixed in 3.26.02026-07-14
CVE-2026-46633 [CRITICAL] CWE-94 CVE-2026-46633: Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quot
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in versi
nvd
CVE-2026-46640P3HIGHCVSS 8.8v>= 3.15.0, < 3.26.02026-07-14
CVE-2026-46640 [HIGH] CWE-94 CVE-2026-46640: Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dyn
Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.() and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template source and executed at template-load time. This issue is fixed in ve
nvd
CVE-2026-48805P3CRITICALCVSS 9.1fixed in 3.27.02026-07-14
CVE-2026-48805 [CRITICAL] CWE-693 CVE-2026-48805: Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(), twig_array_every(), and twig_check_arrow_in_sandbox() to bypass sandbox callable restri
nvd
CVE-2026-48806P3CRITICALCVSS 9.1fixed in 3.27.02026-07-14
CVE-2026-48806 [CRITICAL] CWE-693 CVE-2026-48806: Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in version 3.27.0.
nvd
CVE-2026-46634P3CRITICALCVSS 9.8v>= 3.9.0, < 3.26.02026-07-14
CVE-2026-46634 [CRITICAL] CWE-693 CVE-2026-46634: Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inn
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__ name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and include to render an inner template without security policy
nvd
CVE-2026-48807P3CRITICALCVSS 9.1fixed in 3.27.02026-07-14
CVE-2026-48807 [CRITICAL] CWE-693 CVE-2026-48807: Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully c
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.2
nvd
CVE-2022-39261P3HIGHCVSS 7.5v=> 1.0.0, < 1.44.7v>= 2.0.0, < 2.15.3+1 more2022-09-28
CVE-2022-39261 [HIGH] CWE-22 CVE-2022-39261: Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prio
Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `include` statement to read arbitrary files from outside the templates' directory when using a namespace li
nvd
CVE-2024-45411P3HIGHCVSS 8.6fixed in 3.26.02024-09-09
CVE-2024-45411 [HIGH] CWE-693 CVE-2024-45411: Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not r
Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.
nvd
CVE-2026-49981P3HIGHCVSS 8.2fixed in 3.27.02026-07-14
CVE-2026-49981 [HIGH] CWE-693 CVE-2026-49981: Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function all
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. Th
nvd
CVE-2026-48808P3HIGHCVSS 7.5fixed in 3.27.02026-07-14
CVE-2026-48808 [HIGH] CWE-693 CVE-2026-48808: Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox st
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is
nvd
CVE-2026-46639P3MEDIUMCVSS 6.5v>= 3.24.0, < 3.26.02026-07-14
CVE-2026-46639 [MEDIUM] CWE-693 CVE-2026-46639: Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compi
Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template to read public properties or invoke public getters on o
nvd
CVE-2026-47732P3MEDIUMCVSS 6.5fixed in 3.26.02026-07-14
CVE-2026-47732 [MEDIUM] CWE-863 CVE-2026-47732: Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP s
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operator
nvd
CVE-2026-46629P3MEDIUMCVSS 6.5fixed in 3.26.02026-07-14
CVE-2026-46629 [MEDIUM] CWE-770 CVE-2026-46629: Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and
Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template to allocate many ICU formatter objects that remain pinned for the lifetime of the Twig\Environment. This issue i
nvd
CVE-2026-46627P4MEDIUMCVSS 6.5fixed in 3.26.02026-07-14
CVE-2026-46627 [MEDIUM] CWE-400 CVE-2026-46627: Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template f
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource
nvd
CVE-2026-47730P4MEDIUMCVSS 5.4v>= 3.0.0, < 3.26.02026-07-14
CVE-2026-47730 [MEDIUM] CWE-79 CVE-2026-47730: Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.
nvd
CVE-2026-46637P4MEDIUMCVSS 5.4fixed in 3.26.02026-07-14
CVE-2026-46637 [MEDIUM] CWE-116 CVE-2026-46637: Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twi
Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.
nvd
CVE-2026-46628P4MEDIUMCVSS 5.4fixed in 3.26.02026-07-14
CVE-2026-46628 [MEDIUM] CWE-116 CVE-2026-46628: Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0.
nvd
1 / 2Next →