twenty kayıtları
twenty üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %16,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-26720Kavram kanıtı | An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.twenty · twenty · CWE-94 | Kritik9,8 | — | %1,2 | 2 Mar 2026 |
39İzleyin | CVE-2026-46624İstismar yok | Twenty: SQL Injection via the timeZone fieldtwenty · twenty · CWE-78 | Kritik9,9 | — | %0,7 | 26 May 2026 |
34İzleyin | CVE-2026-44729İstismar yok | Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers)twenty · twenty · CWE-79 | Yüksek8,7 | — | %0,4 | 26 May 2026 |
30İzleyin | CVE-2024-28434İstismar yok | The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0.twenty · twenty · CWE-79 | Yüksek7,6 | — | %0,7 | 25 Mar 2024 |
21İzleyin | CVE-2024-28435İstismar yok | The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.twenty · twenty · CWE-918 | Orta5,4 | — | %0,4 | 25 Mar 2024 |
20İzleyin | CVE-2026-27023İstismar yok | Twenty: SSRF protection bypass via HTTP redirect following in secure HTTP clienttwenty · twenty · CWE-918 | Orta5,0 | — | %0,3 | 5 Mar 2026 |
- CVE-2026-2672039İzleyin
An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.
KritikCVSS 9,8Kavram kanıtıEPSS %1twenty · twenty2 Mar 2026
- CVE-2026-4662439İzleyin
Twenty: SQL Injection via the timeZone field
KritikCVSS 9,9İstismar yokEPSS %1twenty · twenty26 May 2026
- CVE-2026-4472934İzleyin
Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers)
YüksekCVSS 8,7İstismar yokEPSS %0twenty · twenty26 May 2026
- CVE-2024-2843430İzleyin
The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0.
YüksekCVSS 7,6İstismar yokEPSS %1twenty · twenty25 Mar 2024
- CVE-2024-2843521İzleyin
The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.
OrtaCVSS 5,4İstismar yokEPSS %0twenty · twenty25 Mar 2024
- CVE-2026-2702320İzleyin
Twenty: SSRF protection bypass via HTTP redirect following in secure HTTP client
OrtaCVSS 5,0İstismar yokEPSS %0twenty · twenty5 Mar 2026