CVE-2025-70038: Linagora Twake

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allows attackers to execute arbitrary code.

Affected products

  • Linagora Twake: version 2023.q1.1223 only

Published 2026-03-09. Last modified 2026-06-17.