Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ux MEDIUM 5.4
CVE-2026-49216

Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX …

Fix: 2.36.0+
Fix from $1,600 2026-07-17
Ux MEDIUM 5.4
CVE-2026-49215

Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventListener\LiveComponentSubscriber:…

Fix: 2.36.0+
Fix from $1,600 2026-07-17
Ux HIGH 7.5
CVE-2026-49211

Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\EntitySearchUtil::addSearchClau…

Fix: 2.36.0+
Fix from $1,950 2026-07-17
Ux HIGH 7.5
CVE-2026-49212

Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydra…

Fix: 2.36.0+
Fix from $1,950 2026-07-17
Ux MEDIUM 6.5
CVE-2026-49209

Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__inv…

Fix: 2.36.0+
Fix from $1,600 2026-07-17
Ux MEDIUM 6.1
CVE-2026-49210

Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::cre…

Fix: 2.36.0+
Fix from $1,600 2026-07-17
Ux MEDIUM 5.3
CVE-2026-49208

Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit…

Fix: 2.36.0+
Fix from $1,600 2026-07-17
Twig HIGH 8.2
CVE-2026-49981

Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template insta…

Fix: 3.27.0+
Fix from $1,950 2026-07-14
Twig CRITICAL 9.1
CVE-2026-48807

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replac…

Fix: 3.27.0+
Fix from $2,300 2026-07-14
Twig HIGH 7.5
CVE-2026-48808

Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current…

Fix: 3.27.0+
Fix from $1,950 2026-07-14
Twig CRITICAL 9.1
CVE-2026-48805

Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state…

Fix: 3.27.0+
Fix from $2,300 2026-07-14
Twig CRITICAL 9.1
CVE-2026-48806

Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP t…

Fix: 3.27.0+
Fix from $2,300 2026-07-14
Twig MEDIUM 6.5
CVE-2026-47732

Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without co…

Fix: 3.26.0+
Fix from $1,600 2026-07-14
Twig MEDIUM 5.4
CVE-2026-47730

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() in…

Fix: 3.26.0+
Fix from $1,600 2026-07-14
Twig CRITICAL 9.8
CVE-2026-46634

Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template…

Fix: 3.26.0+
Fix from $2,300 2026-07-14
Twig HIGH 8.8
CVE-2026-46640

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker…

Fix: 3.26.0+
Fix from $1,950 2026-07-14
Twig HIGH 8.1
CVE-2026-46638

Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbo…

Fix: 3.26.0+
Fix from $1,950 2026-07-14
Twig MEDIUM 6.5
CVE-2026-46639

Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbo…

Fix: 3.26.0+
Fix from $1,600 2026-07-14
Twig MEDIUM 5.4
CVE-2026-46637

Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe =>…

Fix: 3.26.0+
Fix from $1,600 2026-07-14
Twig CRITICAL 9.8
CVE-2026-46633

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is p…

Fix: 3.26.0+
Fix from $2,300 2026-07-14
Twig MEDIUM 6.5
CVE-2026-46629

Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by tem…

Fix: 3.26.0+
Fix from $1,600 2026-07-14
Twig MEDIUM 6.5
CVE-2026-46627

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, ev…

Fix: 3.26.0+
Fix from $1,600 2026-07-14
Twig MEDIUM 5.4
CVE-2026-46628

Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to em…

Fix: 3.26.0+
Fix from $1,600 2026-07-14
Twig CRITICAL 9.9
CVE-2026-24425

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with te…

Fix: 3.26.0+
Fix from $2,300 2026-05-20
Twig HIGH 8.6
CVE-2024-45411

Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to byp…

Fix: 1.44.8 / 2.16.1+
Fix from $1,950 2024-09-09
Ux Autocomplete MEDIUM 6.5
CVE-2023-41336

ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could successfully submit an entity …

Fix: 2.11.2+
Fix from $1,600 2023-09-11
Twig HIGH 7.5
CVE-2022-39261

Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem…

Fix: 1.44.7 / 2.15.3+
Fix from $1,950 2022-09-28
Twig CRITICAL 9.8
CVE-2022-23614EPSS 8%

Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attac…

Fix: 2.14.11 / 3.3.8+
Fix from $2,300 2022-02-04
Twig CRITICAL 9.8
CVE-2018-13818EPSS 7%

Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is n…

Fix: 2.4.4+
Fix from $2,300 2018-07-10
Twig MEDIUM 6.8
CVE-2015-7809

The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary …

Fix: after 1.19.0
Fix from $1,600 2015-11-06