Twig is a technology platform tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed April 12, 2026; most recent activity July 7, 2026.
A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, was disclosed on June 23, 2026. This flaw affects all versions up to 0.7.2 and allows attackers to exploit unsafe…
A Remote Code Execution vulnerability (CVE-2026-31857) has been identified in Craft CMS versions prior to 5.9.9 and 4.17.4. The flaw exists in the BaseElementSelectConditionRule::getElementIds() method, which improperly…
A critical vulnerability in the Twig template engine affects Ubuntu 26.04 LTS and its derivatives. Discovered on June 8, 2026, the flaw allows an authenticated user to execute arbitrary code by sending specially crafted…
Craft CMS versions 5.9.0 and above prior to 5.10.0 are vulnerable to authenticated remote code execution (RCE) due to a flaw in how the control panel processes the HTTP Referrer header. Users with edit permissions can…