ZeroHour

CVE-2025-24374

CVSS 3.1
4.3 medium
EPSS
<1%p21
Published
()
Modified
Description

Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.

Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.