Known vulnerabilities in php-twig (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:php-twig_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 9
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting php-twig (Debian package) php-twig (Debian package) is affected by 9 known vulnerabilities: 3 high, 5 medium, 1 low Critical High Medium Low

Vulnerabilities (9)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU132001 - Improper Encoding or Escaping of Output
CVE-2026-46628
CWE-116 Medium
No
No
3.5.1-1+deb12u3 20.05.2026 SB2026052091
SB2026060335
#VU131999 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-46633
CWE-94 High
No
No
3.5.1-1+deb12u3 20.05.2026 SB2026052091
SB2026060335
#VU131994 - Allocation of Resources Without Limits or Throttling
CVE-2026-46629
CWE-770 Medium
No
No
3.5.1-1+deb12u3 20.05.2026 SB2026052091
SB2026060335
#VU131993 - Improper Encoding or Escaping of Output
CVE-2026-46637
CWE-116 Medium
No
No
3.5.1-1+deb12u3 20.05.2026 SB2026052091
SB2026060335
#VU131991 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-47730
CWE-79 Medium
No
No
3.5.1-1+deb12u3 20.05.2026 SB2026052091
SB2026060335
#VU102072 - Protection Mechanism Failure
CVE-2024-45411
CWE-693 High
No
No
3.5.1-1+deb12u1 30.12.2024 SB2024123097
SB20241230139
SB2025021858
and 1 more
#VU131987 - Improper Access Control
CVE-2024-51754
CWE-284 Low
No
No
3.5.1-1+deb12u3 06.11.2024 SB2024110669
SB2026060335
#VU67723 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-39261
CWE-22 Medium
No
No
2.14.3-1+deb11u2 28.09.2022 SB2022092839
SB2022092840
SB2022100546
and 7 more
#VU61609 - Security Features
CVE-2022-23614
CWE-254 High
Available
No
2.14.3-1+deb11u1 24.03.2022 SB2022032424
SB2022032425
SB2023031401
and 4 more