twig has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was June 2026 with 4. None have a confirmed exploitation report. The dominant weakness classes are CWE-693 (5) and CWE-863 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- —
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Worst active — by depth score
CVE-2026-49981HighTwig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`41CVE-2026-48808MediumTwig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`28CVE-2026-48807MediumTwig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters28CVE-2026-48806MediumTwig: Sandbox `__toString()` policy bypass via dynamic mapping keys28CVE-2026-48805LowTwig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`14
twig vulnerabilities
CVEs affecting twig, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-49981HighTwig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
CVE-2026-48805LowTwig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
CVE-2026-48806MediumTwig: Sandbox `__toString()` policy bypass via dynamic mapping keys
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
CVE-2026-48807MediumTwig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
CVE-2026-48808MediumTwig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`