Vulnerability record · CVE-2018-13818 · published 10 July 2018
CVE-2018-13818: Symfony twig code injection vulnerability
Symfony · Twig
Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it
Description
Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/twigphp/Twig/blob/2.x/CHANGELOG | Release Notes |
| https://github.com/twigphp/Twig/commit/eddb97148ad779f27e670e1e3f19fb323aedafeb | PatchThird Party Advisory |
| https://github.com/twigphp/Twig/issues/2743 | ExploitThird Party Advisory |
| https://mobile.twitter.com/jameel_nabbo/status/1032593354704515072?s=20 | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/44102/ | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/twigphp/Twig/blob/2.x/CHANGELOG | Release Notes |
| https://github.com/twigphp/Twig/commit/eddb97148ad779f27e670e1e3f19fb323aedafeb | PatchThird Party Advisory |
| https://github.com/twigphp/Twig/issues/2743 | ExploitThird Party Advisory |
| https://mobile.twitter.com/jameel_nabbo/status/1032593354704515072?s=20 | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/44102/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-13818 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-13818), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.