Twenty
4 known vulnerabilities
Top Products
Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in
Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fil
Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request UR
An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts mod
Frequently Asked Questions
How many CVEs affect Twenty?
Twenty has 4 CVE records in our database, including 2 critical and 1 high severity vulnerabilities.
What are the most severe Twenty vulnerabilities?
Twenty has 2 critical severity (CVSS 9.0+) and 1 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Twenty vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Twenty products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Twenty Vulnerabilities
CyberStrike scans your infrastructure for Twenty vulnerabilities and provides real-time remediation guidance.
Get Started