Fabien Potencier
12 exploits
Active since Jul 2018
symfony/twig < 2.4.4 - Server-Side Template Injection via search_key Parameter
CVSS 9.8
Twig 2.0.0-2.14.11 - Remote Code Execution via Sort Filter Arrow Parameter
CVSS 8.8
Twig 2.0.0-2.14.11 - Remote Code Execution via Sort Filter Arrow Parameter
CVSS 8.8
Twig <1.44.8, <2.16.1, <3.14.0 - RCE
CVSS 8.5
Twig <1.44.8, <2.16.1, <3.14.0 - RCE
CVSS 8.5
Twig < 1.38.0 and 2.x < 2.7.0 - Sandbox Information Disclosure via __toString() Method
CVSS 3.7
Twig < 1.44.7, 2.x < 2.15.3, 3.x < 3.4.3 - Path Traversal via Namespace Bypass
CVSS 7.5
Grav < 1.7.42 - Server-Side Template Injection via Twig map() and reduce() Functions
CVSS 8.8
Grav < 1.7.45 - Authenticated Remote Code Execution via Twig Escape Function Redefinition
CVSS 8.8
Twig <1.44.8, <2.16.1, <3.14.0 - RCE
CVSS 8.5
Twig <3.11.2, <3.14.1 - Info Disclosure
CVSS 2.2
Twig 3.16.0-3.18.9 - Cross-Site Scripting via Null Coalescing Operator
CVSS 4.3