Количество 4
Количество 4
CVE-2026-46633
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.
CVE-2026-46633
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.
CVE-2026-46633
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string ...
GHSA-7p85-w9px-jpjp
Twig: PHP code injection via `{% use %}` template name
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-46633 Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0. | CVSS3: 9.8 | 1% Низкий | 28 дней назад | |
CVE-2026-46633 Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0. | CVSS3: 9.8 | 1% Низкий | 28 дней назад | |
CVE-2026-46633 Twig is a template language for PHP. Prior to 3.26.0, Compiler::string ... | CVSS3: 9.8 | 1% Низкий | 28 дней назад | |
GHSA-7p85-w9px-jpjp Twig: PHP code injection via `{% use %}` template name | 1% Низкий | 3 месяца назад |
Уязвимостей на страницу