<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Twig</title>
  <link>https://cvedaily.com/pages/tags/twig.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/twig.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Twig</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:27 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-40495 – FOSSBilling is a free, open-source billing and client management system. Version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40495</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40495</strong></p>
  <p>FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache buster parameters in HTML output, bypassing the `hide_version_public` security setting. The FOSSBilling version is embedded in the query string of every `<script>` and `<link>` tag generated by the `script_tag` and `stylesheet_tag` Twig filters. This i…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45697 – Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45697</guid>
    <pubDate>Fri, 29 May 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45697</strong></p>
  <p>Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). This vulnerability is fixed in 2.2.20 and 3.1.24.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9558 – A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9558</guid>
    <pubDate>Fri, 29 May 2026 11:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9558</strong></p>
  <p>A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24425 – Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24425</guid>
    <pubDate>Wed, 20 May 2026 14:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24425</strong></p>
  <p>Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code wh…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46363 – phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46363</guid>
    <pubDate>Fri, 15 May 2026 19:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46363</strong></p>
  <p>phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ_ADD permission to inject malicious script tags via question or answer parameters, which execute in every visitor's browser when FAQ content is rendered with the raw Twig filt…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46361 – phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46361</guid>
    <pubDate>Fri, 15 May 2026 19:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46361</strong></p>
  <p>phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered with the raw filter, disabling autoescape protection. Attackers with FAQ editor privileges can inject HTML-entity-encoded payloads that bypass html_entity_decode(strip_tags()) processing in SearchController.php, executing arbitrary JavaScript in eve…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44738 – Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44738</guid>
    <pubDate>Mon, 11 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44738</strong></p>
  <p>Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, dumping the entire merged site configuration — including all plugin secrets (SMTP passwords, AWS keys, OAuth client secrets, API tokens) — into the rendered HTML. No administrator privileges are required. This vulnerabilit…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42845 – The form plugin for Grav adds the ability to create and use forms. Prior to 9.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42845</guid>
    <pubDate>Mon, 11 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42845</strong></p>
  <p>The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-content overwrite via file upload (GHSA-w4rc-p66m-x6qq). Public form uploads now strip path components from the POST-supplied filename and hard-block page-content extensions (`md`, `yaml`, `yml`, `json`, `twig`, `ini`) regardless of the configurable dangerous-extensions list. A per…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42842 – The form plugin for Grav adds the ability to create and use forms. Prior to 9.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42842</guid>
    <pubDate>Mon, 11 May 2026 17:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42842</strong></p>
  <p>The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Grav CMS Form plugin's select field template. Taxonomy tag and category values are rendered with the Twig |raw filter in the admin panel, bypassing the global autoescape protection. An editor-level user can inject arbitrary JavaScript that executes in…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42610 – Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42610</guid>
    <pubDate>Mon, 11 May 2026 16:17:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42610</strong></p>
  <p>Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing the grav['accounts'] service. Attacker can programmatically load administrative user objects and extract sensitive data, including Bcrypt password hashes and the security salt. This vulnerability is f…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44298 – Kimai is an open-source time tracking application. From version 2.32.0 to before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44298</guid>
    <pubDate>Fri, 08 May 2026 04:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44298</strong></p>
  <p>Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role System-Admin (ROLE_SYSTE_ADMIN) and the permission upload_invoice_template can upload PDF invoice templates, which can call pdfContext.setOption('associated_files', ...) inside the sandboxed Twig render. This is forwarded to mPDF's SetAssociatedFiles(), whose writer calls file_get_…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1921 – The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1921</guid>
    <pubDate>Tue, 05 May 2026 03:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1921</strong></p>
  <p>The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via the `fsReference` AJAX route. This is due to the `findSourceFile()` method normalizing user-supplied `ref` paths containing `../` directory traversal sequences without validating that the resolved path remains within the intended bundle or content directory. This makes it possib…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-40878 – mailcow: dockerized is an open source groupware/email suite based on docker. In ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40878</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-40878</strong></p>
  <p>mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow web interface passes the raw `$_SERVER['REQUEST_URI']` to Twig as a global template variable and renders it inside a JavaScript string literal in the `setLang()` helper of `base.twig`, relying on Twig's default HTML auto-escaping instead of the context-appropriate `js` escaping…</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26274 – October is a Content Management System (CMS) and web platform. Prior to 3.7.14 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26274</guid>
    <pubDate>Tue, 21 Apr 2026 17:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26274</strong></p>
  <p>October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy that allowed database write operations when cms.safe_mode is enabled. Backend users with Developer permissions could use Twig template markup to execute insert, update, and delete operations on any database table through the query builder, w…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22692 – October is a Content Management System (CMS) and web platform. Versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22692</guid>
    <pubDate>Tue, 14 Apr 2026 17:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22692</strong></p>
  <p>October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature (CMS_SAFE_MODE). Certain methods on the collect() helper were not properly restricted, allowing authenticated users with template editing permissions to bypass sandbox protections. Exploitation requir…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33705 – Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33705</guid>
    <pubDate>Fri, 10 Apr 2026 19:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33705</strong></p>
  <p>Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication via HTTP GET requests. These templates expose internal application logic, variable names, AJAX endpoint URLs, and admin panel structure. This vulnerability is fixed in 1.11.38.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-538</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32629 – phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unaut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32629</guid>
    <pubDate>Thu, 02 Apr 2026 15:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32629</strong></p>
  <p>phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that is syntactically valid per RFC 5321 (quoted local part) yet contains raw HTML — for example "<script>alert(1)</script>"@evil.com. PHP's FILTER_VALIDATE_EMAIL accepts this email as valid. The email is stored in the database without HTML sanitization…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4257 – The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4257</guid>
    <pubDate>Mon, 30 Mar 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4257</strong></p>
  <p>The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig `Twig_Loader_String` template engine without sandboxing, combined with the `cfsPreFill` prefill functionality that allows unauthenticated users to inject arbitrary Twi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27131 – The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27131</guid>
    <pubDate>Mon, 23 Mar 2026 20:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27131</strong></p>
  <p>The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.2, admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key, credentials, and other sensitive configuration data, in addition to running the `hashData()` signing function. This issue wa…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32261 – Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32261</guid>
    <pubDate>Mon, 16 Mar 2026 19:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32261</strong></p>
  <p>Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests when certain events occur. From version 3.0.0 to before version 3.2.0, the Webhooks plugin renders user-supplied template content through Twig’s renderString() function without sandbox protection. This allows an authenticated user with access to the Craft control panel and permis…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31857 – Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31857</guid>
    <pubDate>Wed, 11 Mar 2026 18:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31857</strong></p>
  <p>Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElementIds() method passes user-controlled string input through renderObjectTemplate() -- an unsandboxed Twig rendering function with escaping disabled. Any authenticated Control Panel user (including non-a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-31823 – Sylius is an Open Source eCommerce Framework on Symfony. An authenticated stored...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31823</guid>
    <pubDate>Tue, 10 Mar 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-31823</strong></p>
  <p>Sylius is an Open Source eCommerce Framework on Symfony. An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple places across the shop frontend and admin panel due to unsanitized entity names being rendered as raw HTML. Shop breadcrumbs (shared/breadcrumbs.html.twig): The breadcrumbs macro uses the Twig |raw filter on label values. Since taxon names, product names, an…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28784 – Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28784</guid>
    <pubDate>Wed, 04 Mar 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28784</strong></p>
  <p>Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload using the Twig map filter in text fields that accept Twig input under Settings in the Craft control panel or using the System Messages utility, which could lead to a RCE. For this to work, you must have administrator access to the Craft Control Panel, and allowAdminChanges must be…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28783 – Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-bet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28783</guid>
    <pubDate>Wed, 04 Mar 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28783</strong></p>
  <p>Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be able to successfully execute this attack, you need to either have allowAdminChanges enabled on production, or a compromised admin account, or an account with acces…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28697 – Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-bet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28697</guid>
    <pubDate>Wed, 04 Mar 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28697</strong></p>
  <p>Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). By calling the craft.app.fs.write() method, an attacker can write a malicious PHP script to a web-accessible directory and subseque…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28695 – Craft is a content management system (CMS). There is an authenticated admin RCE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28695</guid>
    <pubDate>Wed, 04 Mar 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28695</strong></p>
  <p>Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain. The create() Twig function exposes Craft::createObject(), which allows instantiation of arbitrary PHP classes with constructor arguments. Combined with the bundled symfony/process depen…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27126 – Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27126</guid>
    <pubDate>Tue, 24 Feb 2026 03:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27126</strong></p>
  <p>Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` component when using the `html` column type. The application fails to sanitize the input, allowing an attacker to execute arbitrary JavaScript when another user views a page with the malicious table fie…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25496 – Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25496</guid>
    <pubDate>Mon, 09 Feb 2026 20:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25496</strong></p>
  <p>Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in the Number field type settings. The Prefix and Suffix fields are rendered using the |md|raw Twig filter without proper escaping, allowing script execution when the Number field is displayed on users' profiles. This issue is patched in…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23476 – FacturaScripts is open-source enterprise resource planning and accounting softwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23476</guid>
    <pubDate>Mon, 02 Feb 2026 23:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23476</strong></p>
  <p>FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected XSS bug in FacturaScripts. The problem is in how error messages get displayed. Twig's | raw filter is used, which skips HTML escaping. When triggering a database error (like passing a string where an integer is expected), the error message includes the input and gets rendered wit…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24127 – Typemill is a flat-file, Markdown-based CMS designed for informational documenta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24127</guid>
    <pubDate>Fri, 23 Jan 2026 23:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24127</strong></p>
  <p>Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fi…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23626 – Kimai is a web-based multi-user time-tracking application. Prior to version 2.46...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23626</guid>
    <pubDate>Sun, 18 Jan 2026 23:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23626</strong></p>
  <p>Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a Twig sandbox with an overly permissive security policy (`DefaultPolicy`) that allows arbitrary method calls on objects available in the template context. An authenticated user with export permissions can deploy a malicious Twig template that extracts sensitive information includ…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68454 – Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68454</guid>
    <pubDate>Mon, 05 Jan 2026 22:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68454</strong></p>
  <p>Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administrator access to the Craft Control Panel, and allowAdminChanges must be enabled, which is against Craft CMS' recommendations for any non-dev environment. Alterna…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66844 – In grav &lt;1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66844</guid>
    <pubDate>Mon, 15 Dec 2025 16:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66844</strong></p>
  <p>In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67648 – Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67648</guid>
    <pubDate>Thu, 11 Dec 2025 00:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67648</strong></p>
  <p>Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page without further processing or input validation. This allows direct code injection into the template via the URL parameter…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66299 – Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66299</guid>
    <pubDate>Mon, 01 Dec 2025 22:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66299</strong></p>
  <p>Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypassing the existing security sandbox. Since the security sandbox does not fully protect the Twig object, it is possible to interact with it (e.g., call methods, rea…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66297 – Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin pan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66297</guid>
    <pubDate>Mon, 01 Dec 2025 21:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66297</strong></p>
  <p>Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the page frontmatter. By injecting malicious Twig expressions, the user can escalate their privileges to admin or execute arbitrary system commands via the scheduler API. This results in both Privilege Escalation (PE) and Remot…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62369 – Xibo is an open source digital signage platform with a web content management sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62369</guid>
    <pubDate>Tue, 04 Nov 2025 22:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62369</strong></p>
  <p>Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating functionality, allowing authenticated users with "System -> Add/Edit custom modules and templates" permissions to manipulate Twig filters and execute arbitrary server-side functions as the w…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-11570 – Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11570</guid>
    <pubDate>Fri, 10 Oct 2025 05:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-11570</strong></p>
  <p>Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data.**Note:**This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and Pattern Lab.The package drupal-pattern-lab/unified-twig-extensions is unmaintained, the fix for thi…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10380 – The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10380</guid>
    <pubDate>Tue, 23 Sep 2025 04:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10380</strong></p>
  <p>The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template Injection in all versions up to, and including, 3.7.19. This is due to insufficient input sanitization and lack of access control when processing custom Twig templates in the Model panel. This makes it possible for authenticated attackers, with author-level access or higher, to e…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57811 – Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57811</guid>
    <pubDate>Mon, 25 Aug 2025 18:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57811</strong></p>
  <p>Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to CVE-2024-52293. This vulnerability has been patched in versions 4.16.6 and 5.8.7.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47946 – Symfony UX is an initiative and set of libraries to integrate JavaScript tools i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47946</guid>
    <pubDate>Mon, 19 May 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47946</strong></p>
  <p>Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. `only()`, `defaults()`, `without()`) ouputs attribute values directly without escaping. If these values are unsafe (e.g. contain user input), this can lead to HTML attribute i…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46731 – Craft is a content management system. Versions of Craft CMS on the 4.x branch pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46731</guid>
    <pubDate>Mon, 05 May 2025 20:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46731</strong></p>
  <p>Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24374 – Twig is a template language for PHP. When using the ?? operator, output escaping...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24374</guid>
    <pubDate>Wed, 29 Jan 2025 16:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24374</strong></p>
  <p>Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-12583 – The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12583</guid>
    <pubDate>Sat, 04 Jan 2025 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-12583</strong></p>
  <p>The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the ser…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-54149 – Winter is a free, open-source content management system (CMS) based on the Larav...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54149</guid>
    <pubDate>Mon, 09 Dec 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-54149</strong></p>
  <p>Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow users with access to the CMS templates sections that modify Twig files to bypass the sandbox placed on Twig files and modify resources such as theme customisation values or modify, or remove, templates in the theme even if not provided dir…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52293 – Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52293</guid>
    <pubDate>Wed, 13 Nov 2024 16:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52293</strong></p>
  <p>Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code Execution on the server via twig SSTI. This is a sequel to CVE-2023-40035. This vulnerability is fixed in 4.12.2 and 5.4.3.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-51755 – Twig is a template language for PHP. In a sandbox, an attacker can access attrib...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51755</guid>
    <pubDate>Wed, 06 Nov 2024 20:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-51755</strong></p>
  <p>Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the security check. This is a BC break. This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known…</p>
  <p><strong>CVSS:</strong> 2.2 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-51754 – Twig is a template language for PHP. In a sandbox, an attacker can call `__toStr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51754</guid>
    <pubDate>Wed, 06 Nov 2024 20:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-51754</strong></p>
  <p>Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments to a function or a filter for instance). This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workaro…</p>
  <p><strong>CVSS:</strong> 2.2 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7129 – The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7129</guid>
    <pubDate>Fri, 13 Sep 2024 06:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7129</strong></p>
  <p>The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45592 – auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor librar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45592</guid>
    <pubDate>Tue, 10 Sep 2024 16:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45592</strong></p>
  <p>auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript injection. This is possible because `%source_label%` in twig macro is not escaped. Therefore script tags can be inserted and are executed. The vulnerability is fixed in versions 6.0.0 and 5.2.6.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45411 – Twig is a template language for PHP. Under some circumstances, the sandbox secur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45411</guid>
    <pubDate>Mon, 09 Sep 2024 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45411</strong></p>
  <p>Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6386 – The WPML plugin for WordPress is vulnerable to Remote Code Execution in all vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6386</guid>
    <pubDate>Wed, 21 Aug 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6386</strong></p>
  <p>The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42356 – Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42356</guid>
    <pubDate>Thu, 08 Aug 2024 15:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42356</strong></p>
  <p>Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current language, currency information. The context object allows also to switch for a short time the scope of the Context as a helper with a callable function. The function can be called also from Twig and as the second parameter…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42355 – Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42355</guid>
    <pubDate>Thu, 08 Aug 2024 15:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42355</strong></p>
  <p>Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silence, but this parameter is not escaped properly and allows execution of code. Update to Shopware 6.6.5.1 or 6.5.8.13 to receive a patch. For older ver…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35191 – Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35191</guid>
    <pubDate>Mon, 20 May 2024 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35191</strong></p>
  <p>Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text.  This has been fixed in Formie 2.1.6.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34082 – Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34082</guid>
    <pubDate>Wed, 15 May 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34082</strong></p>
  <p>Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twig Syntax. This includes Grav user account files - `/grav/user/accounts/*.yaml`. This file stores hashed user password, 2FA secret, and the password reset token. This can allow an adversary to compromise any registered account and read any file in the…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-34461 – Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34461</guid>
    <pubDate>Sat, 04 May 2024 05:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-34461</strong></p>
  <p>Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-24724 – Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24724</guid>
    <pubDate>Wed, 03 Apr 2024 03:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-24724</strong></p>
  <p>Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28119 – Grav is an open-source, flat-file content management system. Prior to version 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28119</guid>
    <pubDate>Thu, 21 Mar 2024 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28119</strong></p>
  <p>Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from grav context, an attacker can redefine the escape function and execute arbitrary commands. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandbo…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28118 – Grav is an open-source, flat-file content management system. Prior to version 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28118</guid>
    <pubDate>Thu, 21 Mar 2024 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28118</strong></p>
  <p>Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Grav context, an attacker can redefine config variable. As a result, attacker can bypass a previous SSTI mitigation. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Tw…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28117 – Grav is an open-source, flat-file content management system. Prior to version 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28117</guid>
    <pubDate>Thu, 21 Mar 2024 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28117</strong></p>
  <p>Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDangerousFunction function, but does not impose restrictions on twig functions like twig_array_map, allowing attackers to bypass the validation and execute arbitrary commands. Twig processing of static pages can be enabled in the front matter by any admini…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23525 – The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks becau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23525</guid>
    <pubDate>Thu, 18 Jan 2024 00:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23525</strong></p>
  <p>The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21628 – PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21628</guid>
    <pubDate>Tue, 02 Jan 2024 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21628</strong></p>
  <p>PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possible to store a cross-site scripting payload in the database. The impact is low because the HTML is not interpreted in BO, thanks to twig's escape mechanism. In FO, the cross-site scripting attack is effective, but only impacts the customer sending it,…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-44382 – October is a Content Management System (CMS) and web platform to assist with dev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44382</guid>
    <pubDate>Fri, 01 Dec 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-44382</strong></p>
  <p>October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitted to provide PHP code to be executed by the CMS due to `cms.safe_mode` being enabled can write specific Twig code to escape the Twig sandbox and exe…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-46734 – Symfony is a PHP framework for web and console applications and a set of reusabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46734</guid>
    <pubDate>Fri, 10 Nov 2023 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-46734</strong></p>
  <p>Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46845 – EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46845</guid>
    <pubDate>Tue, 07 Nov 2023 08:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46845</strong></p>
  <p>EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is running by a user with an administrative privilege.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46245 – Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46245</guid>
    <pubDate>Tue, 31 Oct 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46245</strong></p>
  <p>Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig file, exploiting the software's PDF and HTML rendering functionalities. Version 2.1.0 enables security measures for custom…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43661 – Cachet, the open-source status page system. Prior to the 2.4 branch, a template ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43661</guid>
    <pubDate>Wed, 11 Oct 2023 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43661</strong></p>
  <p>Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Commit 6fb043e109d2a262ce3974e863c54e9e5f5e0587 of the 2.4 branch contains a patch for this issue.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-34448 – Grav is a flat-file content management system. Prior to version 1.7.42, the patc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34448</guid>
    <pubDate>Wed, 14 Jun 2023 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-34448</strong></p>
  <p>Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other built-in functions exposed by Twig's Core Extension that could be used to invoke arbitrary unsafe functions, thereby allowing for remote code execution. A patch in version 1.74.2…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-34252 – Grav is a flat-file content management system. Prior to version 1.7.42, there is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34252</guid>
    <pubDate>Wed, 14 Jun 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-34252</strong></p>
  <p>Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby validation against a denylist of unsafe functions is only performed when the argument passed to filter is a string. However, passing an array as a callable argument allows the validation check to be skipped. Consequently, a low privileged attacker wi…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30179 – CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30179</guid>
    <pubDate>Tue, 13 Jun 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30179</strong></p>
  <p>CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this because only Administrators can add this Twig code, and (by design) Administrators are allowed to do that by default.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32679 – Craft CMS is an open source content management system. In affected versions of C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32679</guid>
    <pubDate>Fri, 19 May 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32679</strong></p>
  <p>Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execution. If the name parameter value is not empty string('') in the View.php's doesTemplateExist() -> resolveTemplate() -> _resolveTemplateInternal() -> _resolveTemplate() function, it returns directly without extension verification, so that arbitrary e…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2017 – Server-side Template Injection (SSTI) in Shopware 6 (&lt;= v6.4.20.0, v6.5.0.0-rc1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2017</guid>
    <pubDate>Mon, 17 Apr 2023 11:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2017</strong></p>
  <p>Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the validation checks in `Shopware\Core\Framework\Adapter\Twig\SecurityExtension` and call any arbitrary PHP function and thus exec…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-19825 – Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-19825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-19825</guid>
    <pubDate>Wed, 15 Feb 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-19825</strong></p>
  <p>Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-19825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-22731 – Shopware is an open source commerce platform based on Symfony Framework and Vue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22731</guid>
    <pubDate>Tue, 17 Jan 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-22731</strong></p>
  <p>Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template to call any global PHP function and thus execute arbitrary code. The attacker must have access to a Twig environment in order to exploit this vulner…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2015-10012 – ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in sumocoders Framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-10012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-10012</guid>
    <pubDate>Tue, 03 Jan 2023 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2015-10012</strong></p>
  <p>** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in sumocoders FrameworkUserBundle up to 1.3.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the file Resources/views/Security/login.html.twig. The manipulation leads to information exposure through error message. Upgrading to version 1.4.0 is able to address this issue. The name of the patch is…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-10012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-39365 – Pimcore is an open source data and experience management platform. Prior to vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39365</guid>
    <pubDate>Thu, 27 Oct 2022 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-39365</strong></p>
  <p>Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution. Version 10.5.9 contains a patch for this issue. As a workaround, one may apply the patch manually.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39261 – Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39261</guid>
    <pubDate>Wed, 28 Sep 2022 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39261</strong></p>
  <p>Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `include` statement to read arbitrary files from outside the templates' directory when using a namespace like `@somewhere/../some.file`. In such a case,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24780 – Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24780</guid>
    <pubDate>Tue, 05 Apr 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24780</strong></p>
  <p>Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23614 – Twig is an open source template language for PHP. When in a sandbox mode, the `a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23614</guid>
    <pubDate>Fri, 04 Feb 2022 23:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23614</strong></p>
  <p>Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the ca…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-21686 – PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21686</guid>
    <pubDate>Wed, 26 Jan 2022 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-21686</strong></p>
  <p>PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32649 – October CMS is a self-hosted content management system (CMS) platform based on t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32649</guid>
    <pubDate>Fri, 14 Jan 2022 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32649</strong></p>
  <p>October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and delete website pages" privileges in the backend is able to execute PHP code by running specially crafted Twig code in the template markup. The issue has been patched in Build 473 (v1.0.473) and v1.1.6. Those unable to u…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41120 – sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41120</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41120</guid>
    <pubDate>Tue, 05 Oct 2021 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41120</strong></p>
  <p>sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was created with autoincremented payment id (/pay-with-paypal/{id}) and therefore it was easy to predict. The problem is that the Credit card form has prefilled "credit card holder" field with the Customer's first and last name and hence this can lead t…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41120">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21264 – October is a free, open-source, self-hosted CMS platform based on the Laravel PH...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21264</guid>
    <pubDate>Mon, 03 May 2021 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21264</strong></p>
  <p>October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE-2020-26231 & CVE-2020-15247. An authenticated backend user with the `cms.manage_pages`, `cms.manage_layouts`, or `cms.manage_partials` permissions who would **normally** not be permitted to provide P…</p>
  <p><strong>CVSS:</strong> 5.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29440 – Grav is a file based Web-platform. Twig processing of static pages can be enable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29440</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29440</guid>
    <pubDate>Tue, 13 Apr 2021 20:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29440</strong></p>
  <p>Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arbitrary code execution and elevate privileges on the instance. The issue was addressed in version 1.7.11.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29440">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-28925 – Bolt before 3.7.2 does not restrict filter options in a Request in the Twig cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28925</guid>
    <pubDate>Wed, 30 Dec 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-28925</strong></p>
  <p>Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-26231 – October is a free, open-source, self-hosted CMS platform based on the Laravel PH...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26231</guid>
    <pubDate>Mon, 23 Nov 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-26231</strong></p>
  <p>October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-15247 (fixed in 1.0.469 and 1.1.0) was discovered that has the same impact as CVE-2020-15247. An authenticated backend user with the cms.manage_pages, cms.manage_layouts, or cms.manage_partials permissions who would normally not be permitted to provide PHP code to be executed by the C…</p>
  <p><strong>CVSS:</strong> 5.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-15247 – October is a free, open-source, self-hosted CMS platform based on the Laravel PH...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15247</guid>
    <pubDate>Mon, 23 Nov 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-15247</strong></p>
  <p>October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.469, an authenticated backend user with the cms.manage_pages, cms.manage_layouts, or cms.manage_partials permissions who would normally not be permitted to provide PHP code to be executed by the CMS due to cms.enableSafeMode being enabled is able…</p>
  <p><strong>CVSS:</strong> 5.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12790 – In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12790</guid>
    <pubDate>Mon, 11 May 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12790</strong></p>
  <p>In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template Injection and credentials disclosure via a crafted Twig template after a semicolon.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11056 – In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11056</guid>
    <pubDate>Thu, 07 May 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11056</strong></p>
  <p>In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which could lead to the execution of Twig code. This has been fixed in 3.9.0.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11467 – An issue was discovered in Deskpro before 2019.8.0. This product enables adminis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11467</guid>
    <pubDate>Wed, 01 Apr 2020 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11467</strong></p>
  <p>An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style/edit-theme-set/template-sources theme templates, and uses TWIG as its template engine. While direct access to self and _self variables was not permitted, one could abuse the accessible variables in one's context to reach a native unserialize functio…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-5226 – Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5226</guid>
    <pubDate>Fri, 24 Jan 2020 22:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-5226</strong></p>
  <p>Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be submitted and sent to the system administrator. Starting with SimpleSAMLphp 1.18.0, a new SimpleSAML\Utils\EMail class was introduced to handle sending emails, implemented as a wrapper of an external dependency. This new wrapper allows us to use Twig templates in order to create t…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-12215 – A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12215</guid>
    <pubDate>Mon, 20 May 2019 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-12215</strong></p>
  <p>A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path of Matomo on the disk, because lastError.file is used in plugins/CorePluginsAdmin/templates/safemode.twig. NOTE: the vendor disputes the significance of this issue, stating "avoid reporting path disclosures, as we don't consider them as security vulnerabilitie…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2019-9942 – A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9942</guid>
    <pubDate>Sat, 23 Mar 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2019-9942</strong></p>
  <p>A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14716 – A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14716</guid>
    <pubDate>Mon, 06 Aug 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14716</strong></p>
  <p>A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-13818 – Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-13818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-13818</guid>
    <pubDate>Tue, 10 Jul 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-13818</strong></p>
  <p>Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-13818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-5233 – Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-5233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-5233</guid>
    <pubDate>Mon, 19 Mar 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-5233</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-6927 – Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Dru...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-6927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-6927</guid>
    <pubDate>Thu, 01 Mar 2018 23:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-6927</strong></p>
  <p>Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function which is used to escape potentially dangerous text before outputting it to HTML (as JavaScript output does not typically go through Twig autoescaping). This function does not correctly handle all methods of injecting malicious HTML, leading to a cross-site scripting vulnerability u…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-6927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9180 – perl-XML-Twig: The option to `expand_external_ents`, documented as controlling e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9180</guid>
    <pubDate>Thu, 22 Dec 2016 21:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9180</strong></p>
  <p>perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-7809 – The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7809</guid>
    <pubDate>Fri, 06 Nov 2015 21:59:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-7809</strong></p>
  <p>The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7809">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
