Linagora
Linagora Twake: vulnerabilities and CVEs
Linagora Twake has 6 published vulnerabilities, 3 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months3
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70039 | Critical (9.8) | 0.38% | — | Mar 9, 2026 | An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223. |
| CVE-2025-70038 | High (8.8) | 0.34% | — | Mar 9, 2026 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allows attackers to execute arbitrary code. |
| CVE-2025-70037 | Medium (6.1) | 0.21% | — | Mar 9, 2026 | An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This allows attackers to obtain sensitive information and execute arbitrary code. |
| CVE-2023-2675 | Critical (9.8) | 0.59% | — | Nov 7, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223. |
| CVE-2023-1665 | Critical (9.8) | 0.62% | — | Mar 27, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0. |
| CVE-2023-0028 | Medium (5.4) | 56% | — | Jan 1, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+. |