pkg:Debian/php-twig

共 29 筆 CVEHIGH8MEDIUM1LOW3

✅ 檢查你的版本

所有已知漏洞

  • HIGH8.8CVE-2026-24425Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attacke…
    from 0
  • HIGH8.8CVE-2022-23614php-twig - security update
    from 0, < 2.14.3-1+deb11u1
  • HIGH8.8CVE-2022-23614php-twig - security update
    from 0, < 2.14.3-1+deb11u1
  • HIGH8.5CVE-2024-45411php-twig - security update
    from 0, < 3.5.1-1+deb12u1
  • HIGH8.5CVE-2024-45411php-twig - security update
    from 0, < 2.14.3-1+deb11u3
  • HIGH8.5CVE-2024-45411php-twig - security update
    from 0, < 2.14.3-1+deb11u3
  • HIGH7.5CVE-2022-39261Twig may load a template outside a configured directory when using the filesystem loader
    from 0, < 2.14.3-1+deb11u2
  • HIGH7.5CVE-2022-39261Twig may load a template outside a configured directory when using the filesystem loader
    from 0, < 2.14.3-1+deb11u2
  • MEDIUM4.3CVE-2025-24374Twig security issue where escaping was missing when using null coalesce operator
    from 0
  • LOW2.2CVE-2024-51755Twig has unguarded calls to `__isset()` and to array-accesses when the sandbox is enabled
    from 0
  • LOW2.2CVE-2024-51754php-twig - security update
    from 0, < 2.14.3-1+deb11u4
  • LOW2.2CVE-2024-51754php-twig - security update
    from 0, < 2.14.3-1+deb11u4
  • CVE-2026-48808(無摘要)
    from 0
  • CVE-2026-48805(無摘要)
    from 0
  • CVE-2026-48807(無摘要)
    from 0
  • CVE-2026-46636(無摘要)
    from 0
  • CVE-2026-48806(無摘要)
    from 0
  • CVE-2026-47732(無摘要)
    from 0
  • CVE-2026-46640Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
    from 0
  • CVE-2026-46639Twig: Sandbox property and method bypass via object-destructuring assignment
    from 0, < 3.26.0-1
  • CVE-2026-46638Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
    from 0
  • CVE-2026-46637Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
    from 0
  • CVE-2026-46635Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
    from 0
  • CVE-2026-46634Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
    from 0
  • CVE-2026-46633Twig: PHP code injection via `{% use %}` template name
    from 0
  • CVE-2026-46629twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments
    from 0
  • CVE-2026-46628Twig: The `spaceless` filter implicitly marks its output as safe
    from 0
  • CVE-2026-47730(無摘要)
    from 0
  • CVE-2026-46627(無摘要)
    from 0