The Twitter Project maintains a social media platform whose vulnerability footprint, while narrow in scope, reflects the exposure inherent to a widely used web application with public-facing user interaction and content-handling workflows. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Twitter Project over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35774MEDIUM server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint. | Dec 29, 2020 | 5.4 | 77 | NO | YES |
CVE-2023-29218HIGH The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coo | Apr 3, 2023 | 7.5 | 27 | NO | NO |
CVE-2019-16263HIGH The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned c | Oct 7, 2019 | 7.4 | 22 | NO | NO |
CVE-2019-5431MEDIUM This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twit | May 6, 2019 | 5.4 | 20 | NO | NO |
CVE-2016-10511MEDIUM The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration endpoint, permitting man-in-the-middle | Sep 18, 2017 | 5.9 | 19 | NO | NO |
CVE-2020-5217MEDIUM In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-supplied input was passed into append | Jan 23, 2020 | 5.8 | 17 | NO | NO |
CVE-2017-0911MEDIUM Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. | Feb 9, 2018 | 5.4 | 17 | NO | NO |
CVE-2020-5216MEDIUM In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append | Jan 23, 2020 | 5.8 | 16 | NO | NO |
CVE-2014-6838MEDIUM The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers t | Sep 30, 2014 | 5.4 | 15 | NO | NO |
The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticat | Sep 17, 2015 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Twitter Project.
Media articles that mention a CVE ID that affects a product developed by Twitter Project — matched by CVE ID, not by vendor name.