İçeriğe atla
Noroxi

twenty kayıtları

twenty üreticisine ait 6 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%16,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

6 kayıt
  • CVE-2026-26720
    39İzleyin

    An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    twenty · twenty2 Mar 2026

  • CVE-2026-46624
    39İzleyin

    Twenty: SQL Injection via the timeZone field

    KritikCVSS 9,9İstismar yokEPSS %1

    twenty · twenty26 May 2026

  • CVE-2026-44729
    34İzleyin

    Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers)

    YüksekCVSS 8,7İstismar yokEPSS %0

    twenty · twenty26 May 2026

  • CVE-2024-28434
    30İzleyin

    The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0.

    YüksekCVSS 7,6İstismar yokEPSS %1

    twenty · twenty25 Mar 2024

  • CVE-2024-28435
    21İzleyin

    The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.

    OrtaCVSS 5,4İstismar yokEPSS %0

    twenty · twenty25 Mar 2024

  • CVE-2026-27023
    20İzleyin

    Twenty: SSRF protection bypass via HTTP redirect following in secure HTTP client

    OrtaCVSS 5,0İstismar yokEPSS %0

    twenty · twenty5 Mar 2026