Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.57% | — | TwigAI | 4/9/2026 | 25/9/2026 | Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into… | |
| Analizada | Media (6) | 0.36% | — | Symfony Twig | 14/7/2026 | 21/7/2026 | Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked… | |
| Analizada | Media (6) | 0.41% | — | Symfony Twig | 14/7/2026 | 17/7/2026 | Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by… | |
| Analizada | Alta (7.1) | 0.37% | — | Symfony Twig | 14/7/2026 | 17/7/2026 | Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This… | |
| Analizada | Alta (7.1) | 0.42% | — | Symfony Twig | 14/7/2026 | 17/7/2026 | Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in version 3.27.0. | |
| Analizada | Media (5.3) | 0.48% | — | Symfony Twig | 14/7/2026 | 17/7/2026 | Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(), twig_array_every(), and twig_check_arrow_in_sandbox() to… | |
| Analizada | Alta (7.1) | 0.40% | — | Symfony Twig | 14/7/2026 | 16/7/2026 | Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional… | |
| Analizada | Media (5.1) | 0.29% | — | Symfony Twig | 14/7/2026 | 21/7/2026 | Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is… | |
| Analizada | Alta (8.7) | 0.64% | — | Symfony Twig | 14/7/2026 | 16/7/2026 | Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the generated template source and executed at… | |
| Analizada | Alta (7.1) | 0.39% | — | Symfony Twig | 14/7/2026 | 16/7/2026 | Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template to read public… | |
| Analizada | Media (6) | 0.47% | — | Symfony Twig | 14/7/2026 | 16/7/2026 | Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, and functions that should have been denied by SecurityPolicy::checkSecurity().… | |
| Analizada | Media (5.1) | 0.30% | — | Symfony Twig | 14/7/2026 | 16/7/2026 | Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is… | |
| Analizada | Media (5.3) | 0.33% | — | Symfony Twig | 14/7/2026 | 15/7/2026 | Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAllowed(), allowing an untrusted template author with column in allowedFilters to… | |
| Analizada | Alta (7.7) | 0.62% | — | Symfony Twig | 14/7/2026 | 29/7/2026 | Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and include to render an… | |
| Analizada | Alta (8.7) | 0.69% | — | Symfony Twig | 14/7/2026 | 16/7/2026 | Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache… | |
| Analizada | Media (5.3) | 0.54% | — | Symfony Twig | 14/7/2026 | 16/7/2026 | Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template to allocate many ICU formatter objects that remain pinned for the lifetime of… | |
| Analizada | Media (5.1) | 0.29% | — | Symfony Twig | 14/7/2026 | 16/7/2026 | Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0. | |
| Analizada | Alta (7.1) | 0.54% | — | Symfony Twig | 14/7/2026 | 16/7/2026 | Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox… | |
| Aplazada | Crítica (9.9) | 0.79% | — | MauticAITwigAI | 29/5/2026 | 21/7/2026 | A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote… | |
| Analizada | Alta (8.7) | 0.76% | — | Symfony Twig | 20/5/2026 | 23/7/2026 | Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the… | |
| Pendiente de análisis | Baja (1.9) | 0.22% | — | Drupal Unified Twig ExtensionsAIDrupal Unified Twig EXTAI | 10/10/2025 | 17/6/2026 | Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data. **Note:** This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and Pattern Lab. The… | |
| Aplazada | Media (6.1) | 0.24% | — | Symfony Ux-twig-componentAISymfony Ux-live-componentAI | 19/5/2025 | 17/6/2026 | Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. `only()`, `defaults()`, `without()`) ouputs attribute values directly without escaping. If… | |
| Aplazada | Media (4.3) | 0.29% | — | TwigAI | 29/1/2025 | 17/6/2026 | Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0. | |
| Aplazada | Baja (2.2) | 0.43% | — | Symfony TwigAI | 6/11/2024 | 17/6/2026 | Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the security check. This is a BC break. This issue has been patched in… | |
| Aplazada | Baja (2.2) | 0.43% | — | Symfony TwigAI | 6/11/2024 | 17/6/2026 | Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments to a function or a filter for instance). This issue has been patched in versions… |