Highlights
Information Disclosure: 1 prior fix. Scrutinize any change in this area.
Slim/Error/Renderers/HtmlErrorRenderer.php: most-fixed (1 issue). Treat as high-risk during review.
1 high-severity fix in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Reflected XSS: Untrusted input placed into error title/description is rendered into HTML without escaping, enabling reflected XSS.
Information Disclosure: Verbose exception output (stack traces, file paths) was leaked to clients by default; now gated behind displayErrorDetails flag.