Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-47730

17 дней назад

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-47730

17 дней назад

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2026-47730

17 дней назад

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Pro ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2g2g-8p8h-fgwm

около 2 месяцев назад

Twig: XSS in profiler HtmlDumper via unescaped template and profile names

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-47730

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.

CVSS3: 5.4
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-47730

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.

CVSS3: 5.4
0%
Низкий
17 дней назад
debian логотип
CVE-2026-47730

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Pro ...

CVSS3: 5.4
0%
Низкий
17 дней назад
github логотип
GHSA-2g2g-8p8h-fgwm

Twig: XSS in profiler HtmlDumper via unescaped template and profile names

0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.