Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

twigphp — Vulnerabilities & Security Advisories 24

Browse all 24 CVE security advisories affecting twigphp. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TwigPHP is a templating engine for PHP primarily used for separating application logic from presentation in web development. Historically, it has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input handling and sandbox bypasses. The project maintains a security-focused approach with regular updates, though past incidents like CVE-2022-41738 (RCE via sandbox escape) highlight ongoing risks. With six CVEs recorded, TwigPHP remains a critical component requiring strict input validation and timely patching to prevent potential compromises in applications relying on its templating capabilities.

Found 24 results / 24Clear Filters
Top products by twigphp: Twig
CVE IDTitleCVSSSeverityPublished
CVE-2026-48807 Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters — TwigCWE-693--2026-07-14
CVE-2026-48806 Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys — TwigCWE-693--2026-07-14
CVE-2026-48808 Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface` — TwigCWE-693--2026-07-14
CVE-2026-48805 Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php` — TwigCWE-693--2026-07-14
CVE-2026-49981 Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template` — TwigCWE-693--2026-07-14
CVE-2026-46637 Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']` — TwigCWE-116--2026-07-14
CVE-2026-46638 Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411) — TwigCWE-693--2026-07-14
CVE-2026-46640 Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation — TwigCWE-94--2026-07-14
CVE-2026-46629 Twig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled arguments — TwigCWE-770--2026-07-14
CVE-2026-47730 Twig: XSS in profiler HtmlDumper via unescaped template and profile names — TwigCWE-79--2026-07-14
CVE-2026-46628 Twig: The `spaceless` filter implicitly marks its output as safe — TwigCWE-116--2026-07-14
CVE-2026-46634 Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name — TwigCWE-693 7.7 High2026-07-14
CVE-2026-46627 Twig: Sandbox resource exhaustion via unbounded `for` / `range()` — TwigCWE-400--2026-07-14
CVE-2026-46633 Twig: PHP code injection via `{% use %}` template name — TwigCWE-94--2026-07-14
CVE-2026-46639 Twig: Sandbox property and method bypass via object-destructuring assignment — TwigCWE-693--2026-07-14
CVE-2026-46635 Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects) — TwigCWE-863--2026-07-14
CVE-2026-47732 Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points — TwigCWE-863--2026-07-14
CVE-2026-24425 Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface — TwigCWE-693 8.8 High2026-05-20
CVE-2025-24374 Twig fixes a security issue where escaping was missing when using null coalesce operator (??) — TwigCWE-74 4.3 Medium2025-01-29
CVE-2024-51754 Unguarded calls to __toString() when nesting an object into an array in Twig — TwigCWE-668 2.2 Low2024-11-06
CVE-2024-51755 Unguarded calls to __isset() and to array-accesses when the sandbox is enabled in Twig — TwigCWE-668 2.2 Low2024-11-06
CVE-2024-45411 Twig has a possible sandbox bypass — TwigCWE-693 8.6 High2024-09-09
CVE-2022-39261 Twig may load a template outside a configured directory when using the filesystem loader — TwigCWE-22 7.5 High2022-09-28
CVE-2022-23614 Code injection in Twig — TwigCWE-74 8.8 High2022-02-04

This page lists every published CVE security advisory associated with twigphp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.