Provides integration for Twig with various Symfony components
100%
Total Score
100
97
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-455080 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. symfony/twig-bridge is vulnerable to Deserialization of Untrusted Data in versions 6.0.0 - 6.4.40, 7.0.0 - 7.4.12, 8.0.0 - 8.0.12 and 8.1.0 - 8.1.0. | 6.0.0 - 6.4.407.0.0 - 7.4.128.0.0 - 8.0.12 +1 more | Medium |
AIKIDO-2026-10865 symfony/twig-bridge is vulnerable to Cross-site Scripting (XSS) in versions 6.4.24 - 6.4.39. | 6.4.24 - 6.4.39 | Low |
CVE-2023-46734 symfony/twig-bridge is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.0.0 - 4.4.51, 5.0.0 - 5.4.31 and 6.0.0 - 6.3.8. | 2.0.0 - 4.4.515.0.0 - 5.4.316.0.0 - 6.3.8 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.25|^4.0 | — | — |
symfony/translation-contracts Version ^2.5|^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant