twenty records
6 published records for vendor twenty.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-26720Proof of concept | An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.twenty · twenty · CWE-94 | Critical9.8 | — | 1.2% | Mar 2, 2026 |
39Monitor | CVE-2026-46624No exploit | Twenty: SQL Injection via the timeZone fieldtwenty · twenty · CWE-78 | Critical9.9 | — | 0.7% | May 26, 2026 |
34Monitor | CVE-2026-44729No exploit | Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers)twenty · twenty · CWE-79 | High8.7 | — | 0.4% | May 26, 2026 |
30Monitor | CVE-2024-28434No exploit | The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0.twenty · twenty · CWE-79 | High7.6 | — | 0.7% | Mar 25, 2024 |
21Monitor | CVE-2024-28435No exploit | The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.twenty · twenty · CWE-918 | Medium5.4 | — | 0.4% | Mar 25, 2024 |
20Monitor | CVE-2026-27023No exploit | Twenty: SSRF protection bypass via HTTP redirect following in secure HTTP clienttwenty · twenty · CWE-918 | Medium5.0 | — | 0.3% | Mar 5, 2026 |
- CVE-2026-2672039Monitor
An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.
CriticalCVSS 9.8Proof of conceptEPSS 1%twenty · twentyMar 2, 2026
- CVE-2026-4662439Monitor
Twenty: SQL Injection via the timeZone field
CriticalCVSS 9.9No exploitEPSS 1%twenty · twentyMay 26, 2026
- CVE-2026-4472934Monitor
Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers)
HighCVSS 8.7No exploitEPSS 0%twenty · twentyMay 26, 2026
- CVE-2024-2843430Monitor
The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0.
HighCVSS 7.6No exploitEPSS 1%twenty · twentyMar 25, 2024
- CVE-2024-2843521Monitor
The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.
MediumCVSS 5.4No exploitEPSS 0%twenty · twentyMar 25, 2024
- CVE-2026-2702320Monitor
Twenty: SSRF protection bypass via HTTP redirect following in secure HTTP client
MediumCVSS 5.0No exploitEPSS 0%twenty · twentyMar 5, 2026