Skip to content
Noroxi

twenty records

6 published records for vendor twenty.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
16.7%
Median publish → KEV
No record has entered KEV

All records

6 records
  • An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    twenty · twentyMar 2, 2026

  • Twenty: SQL Injection via the timeZone field

    CriticalCVSS 9.9No exploitEPSS 1%

    twenty · twentyMay 26, 2026

  • Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers)

    HighCVSS 8.7No exploitEPSS 0%

    twenty · twentyMay 26, 2026

  • The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0.

    HighCVSS 7.6No exploitEPSS 1%

    twenty · twentyMar 25, 2024

  • The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.

    MediumCVSS 5.4No exploitEPSS 0%

    twenty · twentyMar 25, 2024

  • Twenty: SSRF protection bypass via HTTP redirect following in secure HTTP client

    MediumCVSS 5.0No exploitEPSS 0%

    twenty · twentyMar 5, 2026