Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-28434

The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.1%
CVSS Severity
CVSS v3 Score 7.6
Products affected by CVE-2024-28434
  • Twenty » Twenty » Version: 0.3.0
    cpe:2.3:a:twenty:twenty:0.3.0


Contact Us

Shodan ® - All rights reserved