Known Vulnerabilities for Twitter Kit by Twitter
Listed below are 3 of the newest known vulnerabilities associated with "Twitter Kit" by "Twitter".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-92829 json | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all version... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-92161 json | FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 an... | Not Provided | 2026-09-25 | 2026-09-29 |
| CVE-2026-89406 json | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of priv... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-84909 json | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripti... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-83561 json | The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment C... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-56285 json | Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMA... | Not Provided | 2026-06-29 | 2026-07-14 |
| CVE-2026-14987 json | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... | Not Provided | 2026-07-16 | 2026-07-16 |
| CVE-2026-14300 json | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the... | Not Provided | 2026-07-29 | 2026-07-30 |
| CVE-2026-12761 json | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentic... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2019-16263 json | The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the ... | 7.4 - HIGH | 2019-10-07 | 2019-10-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Twitter Kit | 3.4.2 | ||||
| Application | Twitter Kit | 3.4.0 | ||||
| Application | Twitter Kit | 3.2.1 | ||||
| Application | Twitter Kit | 3.2.0 | ||||
| Application | Twitter Kit | 3.1.1 | ||||
| Application | Twitter Kit | 3.1.0 | ||||
| Application | Twitter Kit | 3.0.4 | ||||
| Application | Twitter Kit | 3.0.3 | ||||
| Application | Twitter Kit | 3.0.2 | ||||
| Application | Twitter Kit | 3.0.1 | ||||
| Application | Twitter Kit | 3.0 |