Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Twenty

First CVE: Mar 25, 2024Active for: 2 yearsTotal CVEs: 6

Twenty is a focused customer relationship management and business operations platform whose vulnerability profile concentrates in a single product and skews strongly toward critical-severity outcomes. The recurring exposure traces through web application weaknesses including cross-site scripting, server-side request forgery, code injection, OS command injection, and SQL injection, reflecting input-handling and code-generation risks endemic to customer-facing data platforms. Current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Twenty over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2024
2 years ago
Most Recent CVE
May 26, 2026
59 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-46624CRITICAL
Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY T
May 26, 20269.935NONO
CVE-2026-44729HIGH
Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res)
May 26, 20268.733NONO
CVE-2026-26720CRITICAL
An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.
Mar 2, 20269.833NONO
CVE-2024-28434HIGH
The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code.
Mar 25, 20247.621NONO
CVE-2026-27023MEDIUM
Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request URLs at the request level but did not validate redirect target
Mar 5, 20265.019NONO
CVE-2024-28435MEDIUM
The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.
Mar 25, 20245.418NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
33%
33%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low3 (50.0%)
High0 (0.0%)
None3 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Twenty.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Twenty — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Twenty's Products

View all 2 CNAs →

Top CWEs