Twenty is a focused customer relationship management and business operations platform whose vulnerability profile concentrates in a single product and skews strongly toward critical-severity outcomes. The recurring exposure traces through web application weaknesses including cross-site scripting, server-side request forgery, code injection, OS command injection, and SQL injection, reflecting input-handling and code-generation risks endemic to customer-facing data platforms. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Twenty over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-46624CRITICAL Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY T | May 26, 2026 | 9.9 | 35 | NO | NO |
CVE-2026-44729HIGH Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) | May 26, 2026 | 8.7 | 33 | NO | NO |
CVE-2026-26720CRITICAL An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module. | Mar 2, 2026 | 9.8 | 33 | NO | NO |
CVE-2024-28434HIGH The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code. | Mar 25, 2024 | 7.6 | 21 | NO | NO |
CVE-2026-27023MEDIUM Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request URLs at the request level but did not validate redirect target | Mar 5, 2026 | 5.0 | 19 | NO | NO |
CVE-2024-28435MEDIUM The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload. | Mar 25, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Twenty.
Media articles that mention a CVE ID that affects a product developed by Twenty — matched by CVE ID, not by vendor name.