CVE-2026-47730
EUVD-2026-4456714.07.2026, 22:16
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| symfony | twig | 3.0.0 ≤ 𝑥 < 3.26.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases