Package impact

php Packagist / twig/twig

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-24425 critical 9.9 9.9 17d ago Twig: Possible sandbox bypass when using a source policy
CVE-2026-46633 critical 9.5 17d ago Twig: PHP code injection via `{% use %}` template name
CVE-2026-46639 high 8.0 17d ago Twig: Sandbox property and method bypass via object-destructuring assignment
CVE-2026-46640 high 8.0 17d ago Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
CVE-2026-46628 low 2.5 17d ago Twig: The `spaceless` filter implicitly marks its output as safe
CVE-2026-46635 low 2.5 17d ago Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)