twentyhq
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 4
en
Verify to analyze this security profile
As of 09/20/2026, twentyhq recorded 4 security vulnerabilities in the last 90 days across 1 products, including 3 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, twenty had the most security vulnerabilities in the twentyhq ecosystem, with 4 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-92771Twenty before 2.35.0 Permission Bypass via groupBy-with-records Query | Exploitation statusPublic exploit | FixYes | Affected producttwenty | Published09/16/2026 | SeverityHigh |
CVE-2026-82274Twenty Open Redirect via OAuth Propagator Callback | Exploitation statusPublic exploit | FixYes | Affected producttwenty | Published08/28/2026 | SeverityMedium |
CVE-2026-73069Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution | Exploitation statusPublic exploit | FixYes | Affected producttwenty | Published08/11/2026 | SeverityCritical |
CVE-2026-55583Twenty: Cross-workspace IDOR in AgentTurnResolver | Exploitation statusPublic exploit | FixYes | Affected producttwenty | Published06/24/2026 | SeverityHigh |
CVE-2026-46624Twenty: SQL Injection via the timeZone field | Exploitation statusPublic exploit | FixNot confirmed | Affected producttwenty | Published05/26/2026 | SeverityCritical |
CVE-2026-44729Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers) | Exploitation statusPublic exploit | FixNot confirmed | Affected producttwenty | Published05/26/2026 | SeverityHigh |
CVE-2026-33975twenty-server SSRF protection bypass via IPv4-mapped IPv6 address normalization | Exploitation statusPublic exploit | FixNot confirmed | Affected producttwenty | Published05/05/2026 | SeverityHigh |
CVE-2026-35451Twenty: Stored XSS via BlockNote FileBlock | Exploitation statusPublic exploit | FixYes | Affected producttwenty | Published04/21/2026 | SeverityMedium |
CVE-2026-27023Twenty: SSRF protection bypass via HTTP redirect following in secure HTTP client | Exploitation statusNot known exploited | FixYes | Affected producttwenty | Published03/05/2026 | SeverityMedium |