Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Symfony

First CVE: Dec 31, 2001Active for: 25 yearsTotal CVEs: 33
33.7
VTI Score
Medium

Symfony is a widely adopted PHP web-application framework whose vulnerability footprint, though narrow in product scope, reflects its prominence in the application-development ecosystem. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in core components such as Twig templating and UX utilities, where they manifest through code-injection pathways, protection-mechanism failures, cleartext storage, input-validation gaps, and path-traversal weaknesses that are characteristic of template engines and framework utilities handling untrusted input. Developers should treat Symfony advisories as urgent across affected application codebases; live severity and exploitation metrics are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Symfony over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2001
24 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-46633CRITICAL
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quote
Jul 14, 20269.843NONO
CVE-2026-46640HIGH
Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a Macro
Jul 14, 20268.839NONO
CVE-2026-46634CRITICAL
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall out
Jul 14, 20269.839NONO
CVE-2026-24425CRITICAL
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities t
May 20, 20269.939NONO
CVE-2026-48807CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated
Jul 14, 20269.137NONO
CVE-2026-48805CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow()
Jul 14, 20269.137NONO
CVE-2026-48806CRITICAL
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stri
Jul 14, 20269.136NONO
CVE-2022-23614CRITICAL
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrar
Feb 4, 20229.836NONO
CVE-2026-49981HIGH
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can rema
Jul 14, 20268.235NONO
CVE-2026-48808HIGH
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::ch
Jul 14, 20267.533NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
45%
27%
24%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network32 (97.0%)
Unknown1 (3.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (93.9%)
High1 (3.0%)
Unknown1 (3.0%)
User Interaction
None26 (78.8%)
Unknown1 (3.0%)
Required6 (18.2%)
Privileges Required
Low13 (39.4%)
High0 (0.0%)
None19 (57.6%)
Unknown1 (3.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Symfony.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Symfony — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Symfony's Products

View all 3 CNAs →

Top CWEs