StackRadar

CVE-2026-47730

Low

Advisory

Published 5 Jun 2026In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
2.0
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
44
of 17,781 indexed, latest versions
Container images
27
deployed by those charts
Fix available
1 of 1
affected package

Twig: XSS in profiler HtmlDumper via unescaped template and profile names

Carried by container images the latest versions of 44 of 17,781 indexed charts deploy, on 27 images.

Affected packageAffected versionsFixed inImages
twig/twigcomposerv3.3.3, v3.3.7, v3.3.8, v3.3.10+9 more3.26.027
OSV records
GHSA-2g2g-8p8h-fgwm

Charts affected

44 by stars
ChartLatestAffected imagesRadar Score
mauticone-acre-fundVerified publisher0.1.71 of 3See more

mautic one-acre-fund 0.1.7

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
mautic/mautic:v4-apache94ea4acf4049
twig/twig@v3.8.0
3.26.0

Open the chart page →

2,667
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

2,582
glpiglpi-conteiner0.1.02 of 3See more

glpi glpi-conteiner 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0
vdiogov/glpi-conteiner:latest6945f84f0058
twig/twig@v3.8.0
3.26.0

Open the chart page →

12,170
phpmyadminphpmyadminVerified publisher1.0.31 of 1See more

phpmyadmin phpmyadmin 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

2,582
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
twig/twig@v3.3.7
3.26.0

Open the chart page →

7,052
commonground-gatewaycommonground-gateway1.5.41 of 7See more

commonground-gateway commonground-gateway 1.5.4

1 of the 7 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
twig/twig@v3.4.3
3.26.0

Open the chart page →

9,724
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
twig/twig@v3.3.10
3.26.0

Open the chart page →

7,303
firefly-iiigeek-cookbookVerified publisher0.3.01 of 1See more

firefly-iii geek-cookbook 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
fireflyiii/core:version-5.6.142f4283bd0cf7
twig/twig@v3.3.8
3.26.0

Open the chart page →

2,076
opencatalogiopencatalogi1.0.61 of 8See more

opencatalogi opencatalogi 1.0.6

1 of the 8 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
twig/twig@v3.4.3
3.26.0

Open the chart page →

14,838
repmanrepman-helmchartVerified publisher1.0.121 of 3See more

repman repman-helmchart 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
twig/twig@v3.3.7
3.26.0

Open the chart page →

3,596
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
twig/twig@v3.14.2
3.26.0

Open the chart page →

5,315
user-componentuser-component1.2.01 of 4See more

user-component user-component 1.2.0

1 of the 4 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
twig/twig@v3.3.8
3.26.0

Open the chart page →

7,303
redirectwyrihaximusnetVerified publisher1.1.01 of 1See more

redirect wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
twig/twig@v3.14.0
3.26.0

Open the chart page →

1,581
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
twig/twig@v3.3.10
3.26.0

Open the chart page →

7,342
chart-dnazarenochart-dnazareno0.1.01 of 3See more

chart-dnazareno chart-dnazareno 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
twig/twig@v3.5.0
3.26.0

Open the chart page →

5,778
commonground-gatewaycommonground-gateway-frontend0.1.51 of 4See more

commonground-gateway commonground-gateway-frontend 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
twig/twig@v3.4.3
3.26.0

Open the chart page →

2,825
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
twig/twig@v3.3.10
3.26.0

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
twig/twig@v3.3.10
3.26.0

Open the chart page →

29,033
wordpressdevops0.12.01 of 4See more

wordpress devops 0.12.0

1 of the 4 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
twig/twig@v3.3.10
3.26.0

Open the chart page →

12,992
eav-componenteav-component1.0.01 of 3See more

eav-component eav-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
twig/twig@v3.4.1
3.26.0

Open the chart page →

7,255
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
twig/twig@v3.3.10
3.26.0

Open the chart page →

7,327
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
twig/twig@v3.3.10
3.26.0

Open the chart page →

20,933
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
twig/twig@v3.24.0
3.26.0

Open the chart page →

5,039
firefly-iii-stackfirefly-iii0.10.21 of 4See more

firefly-iii-stack firefly-iii 0.10.2

1 of the 4 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
twig/twig@v3.24.0
3.26.0

Open the chart page →

10,260
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

5,704
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

5,704
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
twig/twig@v3.3.8
3.26.0

Open the chart page →

8,392
glpiglpi-chart0.1.12 of 3See more

glpi glpi-chart 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0
vdiogov/glpi-conteiner:latest6945f84f0058
twig/twig@v3.8.0
3.26.0

Open the chart page →

12,170
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
twig/twig@v3.11.3
3.26.0

Open the chart page →

4,751
wallabaghelmforgeVerified publisher1.3.61 of 3See more

wallabag helmforge 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.26.0

Open the chart page →

2,762
wallabaghpVerified publisher0.1.71 of 1See more

wallabag hp 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.26.0

Open the chart page →

1,136
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
jeboehm/mailserver-web:5.0.929da13edf5aa8
twig/twig@v3.21.1
3.26.0

Open the chart page →

10,897
medewerkercatalogusmedewerkercatalogus1.0.01 of 3See more

medewerkercatalogus medewerkercatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
twig/twig@v3.3.10
3.26.0

Open the chart page →

7,327
fossologymidokura-communityVerified publisher0.2.21 of 2See more

fossology midokura-community 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
fossology/fossology:4.2.18bd1f22ba7bb
twig/twig@v3.4.3
3.26.0

Open the chart page →

3,294
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
twig/twig@v3.4.3
3.26.0

Open the chart page →

9,724
firefly-iiiphntom0.2.101 of 2See more

firefly-iii phntom 0.2.10

1 of the 2 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
phntom/fireflyiii:version-5.7.5f881ea5fbbf1
twig/twig@v3.3.10
3.26.0

Open the chart page →

1,813
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
twig/twig@v3.3.3
3.26.0

Open the chart page →

2,972
phpmyadminsb-helm-charts0.3.01 of 1See more

phpmyadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
twig/twig@v3.5.0
3.26.0

Open the chart page →

5,315
wallabagsebtiz13-chartsVerified publisher0.6.01 of 1See more

wallabag sebtiz13-charts 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.26.0

Open the chart page →

1,136
commonground-gatewayskeleton-pip0.1.71 of 5See more

commonground-gateway skeleton-pip 0.1.7

1 of the 5 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
twig/twig@v3.4.3
3.26.0

Open the chart page →

2,825
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
twig/twig@v3.3.7
3.26.0

Open the chart page →

3,993
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0

Open the chart page →

5,704
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
twig/twig@v3.3.10
3.26.0

Open the chart page →

7,552
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-47730.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
twig/twig@v3.3.3
3.26.0

Open the chart page →

2,534

Container images carrying it

27 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/phpmyadmin:5.2.3-apache:latest3a8a8d6b5289
twig/twig@v3.11.3
3.26.0
7
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
twig/twig@v3.4.3
3.26.0
5
buddy/repman:1.4.0097c897f8b54
twig/twig@v3.3.7
3.26.0
3
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
twig/twig@v3.3.10
3.26.0
3
wallabag/wallabag:2.6.144a527e027e0d
twig/twig@v3.11.3
3.26.0
3
fireflyiii/core:version-6.5.9fe4ecec4c2ba
twig/twig@v3.24.0
3.26.0
2
library/phpmyadmin:5.2.16e75aa8f767c
twig/twig@v3.5.0
3.26.0
2
vdiogov/glpi-conteiner:latest6945f84f0058
twig/twig@v3.8.0
3.26.0
2
ckulka/baikal:0.10.1-nginx434bdd162247
twig/twig@v3.14.2
3.26.0
1
fireflyiii/core:version-5.6.142f4283bd0cf7
twig/twig@v3.3.8
3.26.0
1
fossology/fossology:4.2.18bd1f22ba7bb
twig/twig@v3.4.3
3.26.0
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
twig/twig@v3.21.1
3.26.0
1
mautic/mautic:v4-apache94ea4acf4049
twig/twig@v3.8.0
3.26.0
1
openemr/openemr:6.1.089eaa6d9a4e3
twig/twig@v3.3.8
3.26.0
1
phntom/fireflyiii:version-5.7.5f881ea5fbbf1
twig/twig@v3.3.10
3.26.0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
twig/twig@v3.11.3
3.26.0
1
shyim/shopware:6.4.6.0a951c0e6b836
twig/twig@v3.3.3
3.26.0
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
twig/twig@v3.3.10
3.26.0
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
twig/twig@v3.3.10
3.26.0
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
twig/twig@v3.4.1
3.26.0
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
twig/twig@v3.3.10
3.26.0
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
twig/twig@v3.3.10
3.26.0
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
twig/twig@v3.3.8
3.26.0
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
twig/twig@v3.3.10
3.26.0
1
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
twig/twig@v3.3.3
3.26.0
1
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
twig/twig@v3.14.0
3.26.0
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
twig/twig@v3.3.10
3.26.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.