See how twig compares to other vendors in security performance
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion.
End of life: 12/31/2023, Latest version: 2.16.1
End of life: 12/31/2023, Latest version: 2.16.1
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
End of life: 9/28/2022, Latest version: 1.44.8
End of life: 9/28/2022, Latest version: 1.44.8