CRITICAL9.8CVE-2026-46634Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name from 0, < 3.27.0-0+deb13u1
CRITICAL9.8CVE-2026-46633Twig: PHP code injection via `{% use %}` template name from 0
CRITICAL9.1CVE-2026-48807Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters from 0, < 3.27.0-1
CRITICAL9.1Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
from 0, < 3.27.0-1
CRITICAL9.1Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
from 0
HIGH8.8Twig: Possible sandbox bypass when using a source policy
from 0, < 3.27.0-0+deb13u1
HIGH8.8Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
from 0, < 3.27.0-0+deb13u1
HIGH8.8php-twig - security update
from 0, < 2.14.3-1+deb11u1
HIGH8.8php-twig - security update
from 0, < 2.14.3-1+deb11u1
HIGH8.5php-twig - security update
from 0, < 2.14.3-1+deb11u3
HIGH8.5php-twig - security update
from 0, < 2.14.3-1+deb11u3
HIGH8.5php-twig - security update
from 0, < 3.5.1-1+deb12u1
HIGH8.2Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
from 0
HIGH8.1Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
from 0
HIGH7.5Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
from 0, < 3.27.0-1
HIGH7.5Twig may load a template outside a configured directory when using the filesystem loader
from 0, < 2.14.3-1+deb11u2
HIGH7.5Twig may load a template outside a configured directory when using the filesystem loader
from 0, < 2.14.3-1+deb11u2
MEDIUM6.5Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
from 0
MEDIUM6.5Twig: Sandbox property and method bypass via object-destructuring assignment
from 0, < 3.26.0-1
MEDIUM6.5twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments
from 0
MEDIUM6.5Twig is a template language for PHP.
from 0
MEDIUM5.4Twig: XSS in profiler HtmlDumper via unescaped template and profile names
from 0, < 3.5.1-1+deb12u3
MEDIUM5.4Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
from 0
MEDIUM5.4Twig: The `spaceless` filter implicitly marks its output as safe
from 0
MEDIUM4.3Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
from 0
MEDIUM4.3Twig security issue where escaping was missing when using null coalesce operator
from 0
LOW2.2Twig has unguarded calls to `__isset()` and to array-accesses when the sandbox is enabled
from 0
LOW2.2php-twig - security update
from 0, < 2.14.3-1+deb11u4
LOW2.2php-twig - security update
from 0, < 2.14.3-1+deb11u4
—(no summary)
from 0