Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-46734

19
FAUCET Score

CVE-2023-46734 describes a cross-site scripting (XSS) vulnerability in Symfony and Twig, affecting versions prior to 4.4.51, 5.4.31, and 6.3.8. Certain Twig filters in CodeExtension incorrectly marked output as HTML-safe, allowing unescaped input to be rendered. This medium-severity vulnerability (CVSS 6.1) requires user interaction and can lead to low impact on confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, < 4.4.51CPE matchmatch criteria
cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.4.31CPE matchmatch criteria
cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.3.8CPE matchmatch criteria
cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
>= 2.0.0, < 4.4.51CPE matchmatch criteria
cpe:2.3:a:sensiolabs:twig:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.4.31CPE matchmatch criteria
cpe:2.3:a:sensiolabs:twig:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.68%
Probability of exploitation in next 30 days
EPSS Percentile
48.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0068 is in the 54th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

composerpatch availablevia ghsa
Product: symfony/twig-bridgeFixed in: 6.3.8
composerpatch availablevia ghsa
Product: symfony/twig-bridgeFixed in: 4.4.51
composerpatch availablevia ghsa
Product: symfony/twig-bridgeFixed in: 5.4.31
composerpatch availablevia ghsa
Product: symfony/symfonyFixed in: 6.3.8
composerpatch availablevia ghsa
Product: symfony/symfonyFixed in: 4.4.51
composerpatch availablevia ghsa
Product: symfony/symfonyFixed in: 5.4.31
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-q847-2q57-wmr3medium

Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters

Nov 12, 2023

References

github.com / symfony/symfony/commit/5d095d5feb1322b16450284a04d6bb48d1198f54
Patch
github.com / symfony/symfony/commit/9da9a145ce57e4585031ad4bee37c497353eec7c
Patch
github.com / symfony/symfony/security/advisories/GHSA-q847-2q57-wmr3
Vendor Advisory
lists.debian.org / debian-lts-announce/2023/11/msg00019.html