Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Twilio

First CVE: Nov 20, 2014Active for: 12 yearsTotal CVEs: 3

Twilio operates widely deployed communications and authentication platforms centered on its Authy multi-factor authentication service and broader telephony/messaging infrastructure, representing critical components in user identity and account access flows. The durable signal in its vulnerability profile centers on concurrency and synchronization weaknesses alongside observable discrepancy flaws, reflecting the complexity of state management and timing-sensitive operations in distributed authentication and communications systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
3
Total CVEs
More Total CVEs than 56% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
5.3
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
33.3%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Twilio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 20, 2014
11 years ago
Most Recent CVE
Jul 2, 2024
752 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-39891MEDIUM
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited
Jul 2, 20245.357YESNO
CVE-2020-24655MEDIUM
A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to potentially approve/deny an access request prior to unlocking th
Sep 10, 20205.119NONO
CVE-2014-9023MEDIUM
The Twilio module 7.x-1.x before 7.x-1.9 for Drupal does not properly restrict access to the Twilio administration pages, which allows remote authenticated users to read and modify
Nov 20, 20145.516NONO
View all 3 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products3 CVEs
100%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
Medium
Attack Vector
Local1 (33.3%)
Network1 (33.3%)
Unknown1 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (33.3%)
High1 (33.3%)
Unknown1 (33.3%)
User Interaction
None2 (66.7%)
Unknown1 (33.3%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (66.7%)
Unknown1 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (3 CVEs).

CISA KEV
1 CVE
33.3% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Twilio.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Twilio — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Twilio's Products

View all 1 CNAs →

Top CWEs