7
I Use This!
Inactive
Analyzed about 5 hours ago. based on code collected 1 day ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2026-49981 High Jul 14, 2026 Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instanc more...
v3.22.1, v3.22.0, v3.21.1, v3.21.0, v3.20.0, v3.19.0, v3.18.0, v3.17.1, v3.17.0, v3.16.0
CVE-2026-48808 High Jul 14, 2026 Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current S more...
v3.22.1, v3.22.0, v3.21.1, v3.21.0, v3.20.0, v3.19.0, v3.18.0, v3.17.1, v3.17.0, v3.16.0
CVE-2026-48807 Critical Jul 14, 2026 Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace more...
v3.22.1, v3.22.0, v3.21.1, v3.21.0, v3.20.0, v3.19.0, v3.18.0, v3.17.1, v3.17.0, v3.16.0
CVE-2026-48806 Critical Jul 14, 2026 Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to more...
v3.22.1, v3.22.0, v3.21.1, v3.21.0, v3.20.0, v3.19.0, v3.18.0, v3.17.1, v3.17.0, v3.16.0
CVE-2026-48805 Critical Jul 14, 2026 Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state t more...
v3.22.1, v3.22.0, v3.21.1, v3.21.0, v3.20.0, v3.19.0, v3.18.0, v3.17.1, v3.17.0, v3.16.0
CVE-2026-47732 Medium Jul 14, 2026 Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without cons more...
v3.22.1, v3.22.0, v3.21.1, v3.21.0, v3.20.0, v3.19.0, v3.18.0, v3.17.1, v3.17.0, v3.16.0
CVE-2026-47730 Medium Jul 14, 2026 Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into more...
v3.22.1, v3.22.0, v3.21.1, v3.21.0, v3.20.0, v3.19.0, v3.18.0, v3.17.1, v3.17.0, v3.16.0
CVE-2026-46640 High Jul 14, 2026 Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.() and import-alias dynamic attribute syntax can concatenate an attacker-controlle more...
v3.22.1, v3.22.0, v3.21.1, v3.21.0, v3.20.0, v3.19.0, v3.18.0, v3.17.1, v3.17.0, v3.16.0
CVE-2026-46638 High Jul 14, 2026 Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox more...
v3.22.1, v3.22.0, v3.21.1, v3.21.0, v3.20.0, v3.19.0, v3.18.0, v3.17.1, v3.17.0, v3.16.0
CVE-2026-46637 Medium Jul 14, 2026 Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [ more...
v3.22.1, v3.22.0, v3.21.1, v3.21.0, v3.20.0, v3.19.0, v3.18.0, v3.17.1, v3.17.0, v3.16.0