All CVEs
Vulnerability intelligence

CVE-2026-46633

CWE-94

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.

CVSS Score
High
EPSS — Exploit Probability
0.6%
Riskier than 47% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
NVD entry

1 article across 1 outlet · first covered May 27, 2026 · latest May 27, 2026

Coverage timeline