CVE-2015-7809: Symfony Twig
Medium severity, CVSS 6.8. EPSS: 3.4% chance of exploitation in the next 30 days.
The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.
Affected products
- Symfony Twig: up to and including 1.19.0
Published 2015-11-06. Last modified 2026-06-17.