Security Advisory

CVE-2026-47730

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-14 21:21:10
Last updated 2026-07-21 14:45:11
Assigner GitHub_M
CVSS score 5.1
State PUBLISHED

Description

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.