Twitter's vulnerability footprint centers on web application and platform components spanning its core service, SDKs, and recommendation systems, with a presence among more prominent vendors in the vulnerability landscape. The recurring exposure reflects application-layer and trust-boundary weaknesses including improper certificate validation, injection flaws, cross-site request forgery, authentication issues, and HTTP header manipulation—patterns common to web services handling user input and third-party integrations. Public exploit code has frequently been developed for these vulnerability classes; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Twitter over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35774MEDIUM server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint. | Dec 29, 2020 | 5.4 | 77 | NO | YES |
CVE-2023-29218HIGH The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coo | Apr 3, 2023 | 7.5 | 27 | NO | NO |
CVE-2019-16263HIGH The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned c | Oct 7, 2019 | 7.4 | 22 | NO | NO |
CVE-2019-5431MEDIUM This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twit | May 6, 2019 | 5.4 | 20 | NO | NO |
CVE-2016-10511MEDIUM The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration endpoint, permitting man-in-the-middle | Sep 18, 2017 | 5.9 | 19 | NO | NO |
CVE-2020-5217MEDIUM In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-supplied input was passed into append | Jan 23, 2020 | 5.8 | 17 | NO | NO |
CVE-2017-0911MEDIUM Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. | Feb 9, 2018 | 5.4 | 17 | NO | NO |
CVE-2020-5216MEDIUM In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append | Jan 23, 2020 | 5.8 | 16 | NO | NO |
CVE-2014-6838MEDIUM The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers t | Sep 30, 2014 | 5.4 | 15 | NO | NO |
The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticat | Sep 17, 2015 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Twitter.
Media articles that mention a CVE ID that affects a product developed by Twitter — matched by CVE ID, not by vendor name.