vciy

CVEs we hold for Twigphp

Records whose assigning authority named Twigphp as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-49981Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached…twigphp Twig
CVE-2026-48808Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`twigphp Twig
CVE-2026-48807Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filterstwigphp Twig
CVE-2026-48806Twig: Sandbox `__toString()` policy bypass via dynamic mapping keystwigphp Twig
CVE-2026-48805Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`twigphp Twig
CVE-2026-47732Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion pointstwigphp Twig
CVE-2026-47730Twig: XSS in profiler HtmlDumper via unescaped template and profile namestwigphp Twig
CVE-2026-46640Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilationtwigphp Twig
CVE-2026-46639Twig: Sandbox property and method bypass via object-destructuring assignmenttwigphp Twig
CVE-2026-46638Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)twigphp Twig
CVE-2026-46637Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`twigphp Twig; twig cssinliner-extra; twig markdown-extra
CVE-2026-46636Twig: Sandbox method allowlist bypass via `Markup` subclasstwigphp Twig
CVE-2026-46635Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)twigphp Twig
CVE-2026-46634Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template nametwigphp Twig
CVE-2026-46633Twig: PHP code injection via `{% use %}` template nametwigphp Twig
CVE-2026-46629Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled argumentstwigphp Twig
CVE-2026-46628Twig: The `spaceless` filter implicitly marks its output as safetwigphp Twig
CVE-2026-46627Twig: Sandbox resource exhaustion via unbounded `for` / `range()`twigphp Twig
CVE-2026-24425Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterfacetwigphp Twig
CVE-2025-24374Twig fixes a security issue where escaping was missing when using null coalesce operator (??)twigphp Twig
CVE-2024-51755Unguarded calls to __isset() and to array-accesses when the sandbox is enabled in Twigtwigphp Twig
CVE-2024-51754Unguarded calls to __toString() when nesting an object into an array in Twigtwigphp Twig
CVE-2024-45411Twig has a possible sandbox bypasstwigphp Twig
CVE-2022-39261Twig may load a template outside a configured directory when using the filesystem loadertwigphp Twig
CVE-2022-23614Code injection in Twigtwigphp Twig

25 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.