Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-46637

28 дней назад

Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-46637

28 дней назад

Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2026-46637

28 дней назад

Twig is a template language for PHP. Prior to 3.26.0, several filters ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-jv8m-2544-3pg3

3 месяца назад

Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-46637

Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.

CVSS3: 5.4
0%
Низкий
28 дней назад
nvd логотип
CVE-2026-46637

Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0.

CVSS3: 5.4
0%
Низкий
28 дней назад
debian логотип
CVE-2026-46637

Twig is a template language for PHP. Prior to 3.26.0, several filters ...

CVSS3: 5.4
0%
Низкий
28 дней назад
github логотип
GHSA-jv8m-2544-3pg3

Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`

0%
Низкий
3 месяца назад

Уязвимостей на страницу