September 8, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-46633NVD

Vulnerability Summary

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.
Severity Level
UNKNOWN
Published Date
May 21, 2026
Last Modified
Jul 16, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.64%Probability
Root Weakness (CWE)
N/A