Записи twenty
6 опубликованных записей вендора twenty.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 16,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2026-26720Proof of concept | An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.twenty · twenty · CWE-94 | Критическая9,8 | — | 1,2 % | 2 мар. 2026 г. |
39Наблюдать | CVE-2026-46624Эксплойта нет | Twenty: SQL Injection via the timeZone fieldtwenty · twenty · CWE-78 | Критическая9,9 | — | 0,7 % | 26 мая 2026 г. |
34Наблюдать | CVE-2026-44729Эксплойта нет | Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers)twenty · twenty · CWE-79 | Высокая8,7 | — | 0,4 % | 26 мая 2026 г. |
30Наблюдать | CVE-2024-28434Эксплойта нет | The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0.twenty · twenty · CWE-79 | Высокая7,6 | — | 0,7 % | 25 мар. 2024 г. |
21Наблюдать | CVE-2024-28435Эксплойта нет | The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.twenty · twenty · CWE-918 | Средняя5,4 | — | 0,4 % | 25 мар. 2024 г. |
20Наблюдать | CVE-2026-27023Эксплойта нет | Twenty: SSRF protection bypass via HTTP redirect following in secure HTTP clienttwenty · twenty · CWE-918 | Средняя5,0 | — | 0,3 % | 5 мар. 2026 г. |
- CVE-2026-2672039Наблюдать
An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.
КритическаяCVSS 9,8Proof of conceptEPSS 1 %twenty · twenty2 мар. 2026 г.
- CVE-2026-4662439Наблюдать
Twenty: SQL Injection via the timeZone field
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %twenty · twenty26 мая 2026 г.
- CVE-2026-4472934Наблюдать
Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers)
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %twenty · twenty26 мая 2026 г.
- CVE-2024-2843430Наблюдать
The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0.
ВысокаяCVSS 7,6Эксплойта нетEPSS 1 %twenty · twenty25 мар. 2024 г.
- CVE-2024-2843521Наблюдать
The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %twenty · twenty25 мар. 2024 г.
- CVE-2026-2702320Наблюдать
Twenty: SSRF protection bypass via HTTP redirect following in secure HTTP client
СредняяCVSS 5,0Эксплойта нетEPSS 0 %twenty · twenty5 мар. 2026 г.