Known Vulnerabilities for Twitter Kit by Twitter
Listed below are 3 of the newest known vulnerabilities associated with "Twitter Kit" by "Twitter".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56285 json | Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMA... | Not Provided | 2026-06-29 | 2026-07-14 |
| CVE-2026-53736 json | Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler tha... | Not Provided | 2026-06-10 | 2026-06-11 |
| CVE-2026-14987 json | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... | Not Provided | 2026-07-16 | 2026-07-16 |
| CVE-2026-14300 json | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the... | Not Provided | 2026-07-29 | 2026-07-30 |
| CVE-2026-12761 json | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentic... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2019-16263 json | The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the ... | 7.4 - HIGH | 2019-10-07 | 2019-10-09 |
| CVE-2019-5431 json | This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable ... | 5.4 - MEDIUM | 2019-05-06 | 2020-10-16 |
| CVE-2018-25364 json | Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries... | 5.4 - MEDIUM | 2026-05-25 | 2026-05-26 |
| CVE-2018-25363 json | Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete p... | 5.4 - MEDIUM | 2026-05-25 | 2026-05-26 |
| CVE-2018-25362 json | Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by ... | 5.4 - MEDIUM | 2026-05-25 | 2026-05-26 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Twitter Kit | 3.4.2 | ||||
| Application | Twitter Kit | 3.4.0 | ||||
| Application | Twitter Kit | 3.2.1 | ||||
| Application | Twitter Kit | 3.2.0 | ||||
| Application | Twitter Kit | 3.1.1 | ||||
| Application | Twitter Kit | 3.1.0 | ||||
| Application | Twitter Kit | 3.0.4 | ||||
| Application | Twitter Kit | 3.0.3 | ||||
| Application | Twitter Kit | 3.0.2 | ||||
| Application | Twitter Kit | 3.0.1 | ||||
| Application | Twitter Kit | 3.0 |