CVE-2026-47730: Symfony Twig

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0.

Affected products

  • Symfony Twig: from 3.0.0, before 3.26.0 (fixed in 3.26.0)

Published 2026-07-14. Last modified 2026-07-21.