Twig Development Team maintains a template engine widely used in PHP applications for rendering dynamic content, with a focused vulnerability footprint concentrated in the core Twig product. The observed weakness classes reflect parser and template-processing complexity rather than a broad structural pattern; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Twig Development Team over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-1361HIGH Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links. | Jul 19, 2001 | 7.5 | 19 | NO | NO |
CVE-2001-1348HIGH TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter. | May 28, 2001 | 7.5 | 19 | NO | NO |
CVE-2000-1166HIGH Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying | Jan 9, 2001 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Twig Development Team.
Media articles that mention a CVE ID that affects a product developed by Twig Development Team — matched by CVE ID, not by vendor name.