Vulnerabilidades em twigphp
24 resultadosAnálise Vexday
Twig PHP apresenta 24 vulnerabilidades na base com 18 publicadas nos últimos 90 dias, indicando ritmo acelerado de descobertas, mas nenhuma está sendo explorada ativamente em campo (KEV vazio). Ausência de críticas severas e nenhuma exploração em uso real reduzem o risco imediato, embora a frequência recente de divulgações sugira atenção contínua ao modelo de segurança do projeto, particularmente em relação à CWE-693 (dependência insegura de componentes dinâmicos).
CVE-2022-23614HIGHCode injection in TwigEPSS 8.2%CVE-2022-39261HIGHTwig may load a template outside a configured directory when using the filesystem loaderEPSS 2.5%CVE-2024-45411HIGHTwig has a possible sandbox bypassEPSS 0.8%CVE-2026-24425HIGHTwig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterfaceEPSS 0.8%CVE-2026-46633HIGHTwig: PHP code injection via `{% use %}` template nameEPSS 0.6%CVE-2024-51754LOWUnguarded calls to __toString() when nesting an object into an array in TwigEPSS 0.4%CVE-2026-46634HIGHTwig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template nameEPSS 0.4%CVE-2024-51755LOWUnguarded calls to __isset() and to array-accesses when the sandbox is enabled in TwigEPSS 0.4%CVE-2026-46640HIGHTwig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilationEPSS 0.4%CVE-2026-46627HIGHTwig: Sandbox resource exhaustion via unbounded `for` / `range()`EPSS 0.4%CVE-2026-47732HIGHTwig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion pointsEPSS 0.4%CVE-2026-46639HIGHTwig: Sandbox property and method bypass via object-destructuring assignmentEPSS 0.4%CVE-2026-46629MEDIUMTwig: Unbounded formatter memoisation in twig/intl-extra keyed on template-controlled argumentsEPSS 0.3%CVE-2026-46635MEDIUMTwig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)EPSS 0.3%CVE-2025-24374MEDIUMTwig fixes a security issue where escaping was missing when using null coalesce operator (??)EPSS 0.3%CVE-2026-48805MEDIUMTwig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`EPSS 0.3%CVE-2026-46638MEDIUMTwig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)EPSS 0.3%CVE-2026-48808MEDIUMTwig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`EPSS 0.2%CVE-2026-48806HIGHTwig: Sandbox `__toString()` policy bypass via dynamic mapping keysEPSS 0.2%CVE-2026-48807HIGHTwig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filtersEPSS 0.2%