Linagora develops communication and collaboration platforms including Twake and Hublin, which serve team messaging and conferencing functions in organizational deployments. The vendor's vulnerability profile concentrates in application-layer input handling and access control, with recurring issues in cross-site scripting, path traversal, OS command injection, open redirects, and authentication-bypass patterns, and vulnerabilities affecting the portfolio skew strongly toward critical severity. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linagora over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0028MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.
| Jan 1, 2023 | 5.4 | 40 | NO | NO |
CVE-2023-1665CRITICAL Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0. | Mar 27, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-2675CRITICAL Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223. | Nov 7, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-70039CRITICAL An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223. | Mar 9, 2026 | 9.8 | 27 | NO | NO |
CVE-2025-70038HIGH An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allows attackers to execute arbitrar | Mar 9, 2026 | 8.8 | 25 | NO | NO |
CVE-2019-1010205HIGH LINAGORA hublin latest (commit 72ead897082403126bf8df9264e70f0a9de247ff) is affected by: Directory Traversal. The impact is: The vulnerability allows an attacker to access any file | Jul 23, 2019 | 7.5 | 22 | NO | NO |
CVE-2025-70037MEDIUM An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This allows attackers to obtain sensitive information and execute | Mar 9, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linagora.
Media articles that mention a CVE ID that affects a product developed by Linagora — matched by CVE ID, not by vendor name.