Back to Database
Status published
Medium
CVE-2025-24374
Twig fixes a security issue where escaping was missing when using null coalesce operator (??)
Vulnerability Description
Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-24374
Credits & Attribution
No credits recorded in the NVD database.
References
More from twigphp
View All →CVE-2024-51755
Unguarded calls to __isset() and to array-accesses when the sandbox is enabled in Twig
Low
2.2
CVE-2024-51754
Unguarded calls to __toString() when nesting an object into an array in Twig
Low
2.2
CVE-2024-45411
Twig has a possible sandbox bypass
High
8.6
CVE-2022-39261
Twig may load a template outside a configured directory when using the filesystem loader
High
7.5
CVE-2022-23614
Code injection in Twig
High
8.8
Affected Vendor
twigphp
View all reports →Affected Software
Twig
Vulnerable Versions:
>= 3.16.0, < 3.19.0
Timeline
Official Publish:
January 29th, 2025
Last Modified:
January 29th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N