Symfony

Twig

25 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 14.07.2026 21:19:54
  • Zuletzt bearbeitet 16.07.2026 03:11:52

Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is f...

  • EPSS 0.42%
  • Veröffentlicht 14.07.2026 21:19:17
  • Zuletzt bearbeitet 29.07.2026 19:16:46

Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed te...

  • EPSS 0.39%
  • Veröffentlicht 14.07.2026 21:15:17
  • Zuletzt bearbeitet 16.07.2026 16:19:08

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This is...

  • EPSS 0.64%
  • Veröffentlicht 14.07.2026 21:14:24
  • Zuletzt bearbeitet 16.07.2026 05:16:19

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the st...

  • EPSS 0.35%
  • Veröffentlicht 14.07.2026 21:13:42
  • Zuletzt bearbeitet 16.07.2026 03:11:02

Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker w...

  • EPSS 0.3%
  • Veröffentlicht 14.07.2026 21:12:56
  • Zuletzt bearbeitet 15.07.2026 20:19:05

Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAllowed(), al...

  • EPSS 0.36%
  • Veröffentlicht 14.07.2026 21:12:13
  • Zuletzt bearbeitet 16.07.2026 03:06:57

Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toStr...

  • EPSS 0.76%
  • Veröffentlicht 20.05.2026 14:16:38
  • Zuletzt bearbeitet 23.07.2026 12:10:00

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filter...

  • EPSS 0.85%
  • Veröffentlicht 09.09.2024 19:15:13
  • Zuletzt bearbeitet 21.11.2024 09:37:44

Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.

  • EPSS 2.47%
  • Veröffentlicht 28.09.2022 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:17:54

Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `in...